Code42 provides simple, fast detection and response to everyday data loss from insider threats by focusing on customer data on endpoints and the cloud
Supported Actions
- test connectivity: Validate the asset configuration for connectivity using supplied configuration
- on poll: Callback action for the on_poll ingest functionality
- get session details: Get the details of a session
- run query: Search for file events using EventQuery
- search sessions: Search for sessions using optional filters
- run advanced query: Execute an advanced file event query using a json filter definition
- set session state: Update the state of one or more sessions
- get actor by id: Retrieve details for a single actor by id
- get actor by name: Retrieve details for a single actor by name
- list users: List Code42 users with optional filters
- deactivate user: Deactivate a Code42 user
- reactivate user: Reactivate a Code42 user
- get user: Retrieve details for a single user
- create case: Create a new case
- update case: Update details for an existing case
- close case: Close an open case
- add case event: Attach file events to a case
- add legalhold custodian: Add a custodian to a legal hold matter
- remove legalhold custodian: Remove a custodian from a legal hold matter
- update actor: Update actor metadata and monitoring dates
- list cases: List cases with optional filters
- list available watchlists: List watchlists available to an actor
- get watchlist id by name: Resolve a watchlist ID either by its type (ex: `DEPARTING_EMPLOYEE`) or its title in the case of `CUSTOM` watchlists
- create watchlist: Create a new watchlist
- delete watchlist: Delete a watchlist
- add actors to watchlist: Add actors to a watchlist
- remove actors from watchlist: Remove actors from a watchlist
- list actors in watchlist: List actors currently in a watchlist
- hunt file: Hunt for a file in the Incydr platform