RA2311: Collect File
Summary
ID | RA2311 |
---|---|
Brief Description | Collect a specific file from a (remote) host or a system |
Author | Cyberok |
Creation Date | 2023/03/03 |
Requirements |
|
References | |
Response Stage | Identification |
Response Actions Implementations |
Description
File Collection lets you collect objects directly from any host. Basically there is dozen ways to collect file, conditionally , they can be divided into two groups:
-
manually performed
- SCP
- SFTP
- Powershell and etc...
-
automated
- XDR solution
- SOAR implementation
- Scripted selfmade solution and etc...