<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Antivirus/Malware/EDR on SolCyber Knowledgebase</title><link>https://kb.solcyber.com/supported-data-sources-categories/antivirus-malware-edr/</link><description>Recent content in Antivirus/Malware/EDR on SolCyber Knowledgebase</description><generator>Hugo</generator><language>en</language><atom:link href="https://kb.solcyber.com/supported-data-sources-categories/antivirus-malware-edr/index.xml" rel="self" type="application/rss+xml"/><item><title>SentinelOne</title><link>https://kb.solcyber.com/supported-data-sources-categories/antivirus-malware-edr/sentinel-one/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/supported-data-sources-categories/antivirus-malware-edr/sentinel-one/</guid><description>&lt;ul&gt;
&lt;li&gt;Log in to the SentinelOne &lt;strong&gt;Management Console&lt;/strong&gt; using the &lt;strong&gt;Administrator&lt;/strong&gt; username for the account.&lt;/li&gt;
&lt;li&gt;Copy and save the &lt;strong&gt;URL&lt;/strong&gt; of your login.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Note:&lt;/strong&gt; The host URL information will be similar to the following: &lt;a href="https://usa-partners.sentinelone.net/"&gt;https://usa-partners.sentinelone.net/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;In the &lt;strong&gt;Management Console&lt;/strong&gt;, click &lt;strong&gt;Settings&lt;/strong&gt; &amp;gt; &lt;strong&gt;USERS&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Select your admin user account and click &lt;strong&gt;Generate API token&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src="https://kb.solcyber.com/assets/image%20%28227%29.png" alt="" /&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Copy and save the token&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src="https://kb.solcyber.com/assets/image%20%28217%29.png" alt="" /&gt;&lt;/p&gt;
&lt;blockquote class='book-hint note' &gt;&lt;div class="kb-alert-icon" aria-hidden="true"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2.2" stroke-linecap="round" stroke-linejoin="round"&gt;&lt;circle cx="12" cy="12" r="10"/&gt;&lt;path d="M12 16v-4"/&gt;&lt;path d="M12 8h.01"/&gt;&lt;/svg&gt;&lt;/div&gt;&lt;div class="kb-alert-body"&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; You will need to provide this token to SolCyber.&lt;/p&gt;</description></item><item><title>Crowdstrike</title><link>https://kb.solcyber.com/supported-data-sources-categories/antivirus-malware-edr/crowdstrike/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/supported-data-sources-categories/antivirus-malware-edr/crowdstrike/</guid><description>&lt;h2 id="crowdstrike-falcon-streaming-api"&gt;CrowdStrike Falcon Streaming API&lt;a class="anchor" href="#crowdstrike-falcon-streaming-api"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Log in to Crowdstrike and then navigate to the &lt;strong&gt;Support and Resources &amp;gt; API Clients and Keys&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;figure&gt;&lt;img src="https://kb.solcyber.com/assets/Screenshot 2024-06-21 at 4.40.27 PM.png" alt="" width="407"&gt;&lt;figcaption&gt;&lt;/figcaption&gt;&lt;/figure&gt;
&lt;ul&gt;
&lt;li&gt;Click &lt;strong&gt;Create new API Client&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Enter a name in &lt;strong&gt;Client Name&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote class='book-hint note' &gt;&lt;div class="kb-alert-icon" aria-hidden="true"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2.2" stroke-linecap="round" stroke-linejoin="round"&gt;&lt;circle cx="12" cy="12" r="10"/&gt;&lt;path d="M12 16v-4"/&gt;&lt;path d="M12 8h.01"/&gt;&lt;/svg&gt;&lt;/div&gt;&lt;div class="kb-alert-body"&gt;
&lt;p&gt;&lt;strong&gt;Example:&lt;/strong&gt; Securonix_client.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Select the &lt;strong&gt;Read&lt;/strong&gt; right for the following options:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Detections&lt;/li&gt;
&lt;li&gt;Incidents&lt;/li&gt;
&lt;li&gt;Event streams&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click &lt;strong&gt;Create&lt;/strong&gt;. The API client is now created.&lt;/p&gt;</description></item></channel></rss>