Salta ai contenuti

Vectra AI Commands

Comprehensive Vectra AI platform commands and workflows for network detection and response (NDR).

Platform API Authentication

CommandDescription
curl -H "Authorization: Token <token>" <endpoint>API authentication
vectra-cli auth loginLogin to Vectra platform
vectra-cli auth logoutLogout from platform
vectra-cli auth statusCheck authentication status
export VECTRA_TOKEN=<token>Set environment token
export VECTRA_URL=<url>Set platform URL

Detection Management

CommandDescription
GET /api/v3.3/detectionsList all detections
GET /api/v3.3/detections/{id}Get detection details
PATCH /api/v3.3/detections/{id}Update detection
DELETE /api/v3.3/detections/{id}Delete detection
GET /api/v3.3/detections?state=activeFilter active detections
GET /api/v3.3/detections?certainty=highFilter by certainty

Host Management

CommandDescription
GET /api/v3.3/hostsList all hosts
GET /api/v3.3/hosts/{id}Get host details
PATCH /api/v3.3/hosts/{id}Update host information
GET /api/v3.3/hosts?threat_score_gte=50Filter by threat score
GET /api/v3.3/hosts?certainty_score_gte=80Filter by certainty score

Account Management

CommandDescription
GET /api/v3.3/accountsList all accounts
GET /api/v3.3/accounts/{id}Get account details
PATCH /api/v3.3/accounts/{id}Update account
GET /api/v3.3/accounts?privilege_level=adminFilter by privilege level
GET /api/v3.3/accounts?threat_score_gte=50Filter by threat score

Campaign Management

CommandDescription
GET /api/v3.3/campaignsList all campaigns
GET /api/v3.3/campaigns/{id}Get campaign details
PATCH /api/v3.3/campaigns/{id}Update campaign
GET /api/v3.3/campaigns?state=activeFilter active campaigns

Assignment Management

CommandDescription
GET /api/v3.3/assignmentsList assignments
POST /api/v3.3/assignmentsCreate assignment
GET /api/v3.3/assignments/{id}Get assignment details
PATCH /api/v3.3/assignments/{id}Update assignment
DELETE /api/v3.3/assignments/{id}Delete assignment

Threat Intelligence

CommandDescription
GET /api/v3.3/threat_feedsList threat feeds
POST /api/v3.3/threat_feedsCreate threat feed
GET /api/v3.3/threat_feeds/{id}Get threat feed details
PATCH /api/v3.3/threat_feeds/{id}Update threat feed
DELETE /api/v3.3/threat_feeds/{id}Delete threat feed

Search and Filtering

CommandDescription
GET /api/v3.3/search/detectionsSearch detections
GET /api/v3.3/search/hostsSearch hosts
GET /api/v3.3/search/accountsSearch accounts
GET /api/v3.3/detections?ordering=-threat_scoreOrder by threat score
GET /api/v3.3/detections?page_size=100Set page size

MCP Server Integration

CommandDescription
vectra-mcp installInstall Vectra MCP server
vectra-mcp configureConfigure MCP server
vectra-mcp startStart MCP server
vectra-mcp stopStop MCP server
vectra-mcp statusCheck MCP server status

AI Assistant Commands

CommandDescription
vectra-mcp claude connectConnect to Claude Desktop
vectra-mcp cursor connectConnect to Cursor IDE
vectra-mcp chat enableEnable chat interface
vectra-mcp investigate <query>AI-assisted investigation
vectra-mcp visualize <data>Generate visualizations

Incident Investigation

CommandDescription
vectra-cli investigate --host <host-id>Investigate host
vectra-cli investigate --detection <detection-id>Investigate detection
vectra-cli timeline --host <host-id>Generate host timeline
vectra-cli timeline --account <account-id>Generate account timeline
vectra-cli correlate --detection <detection-id>Correlate detections

Response Actions

CommandDescription
vectra-cli response block --host <host-id>Block host
vectra-cli response isolate --host <host-id>Isolate host
vectra-cli response quarantine --account <account-id>Account di quarantena
vectra-cli response whitelist --host <host-id>Host whitelist
vectra-cli response unblock --host <host-id>Sblocca host

Reporting and Analytics

ComandoDescrizione
GET /api/v3.3/reportsElenca report disponibili
POST /api/v3.3/reportsGenera report
GET /api/v3.3/reports/{id}Ottieni dettagli report
GET /api/v3.3/analytics/summaryOttieni riepilogo analytics
GET /api/v3.3/analytics/trendsOttieni analisi delle tendenze

Configuration Management

ComandoDescrizione
GET /api/v3.3/settingsOttieni impostazioni piattaforma
PATCH /api/v3.3/settingsAggiorna impostazioni
GET /api/v3.3/sensorsElenco sensori
GET /api/v3.3/sensors/{id}Ottieni dettagli sensore
PATCH /api/v3.3/sensors/{id}Aggiorna configurazione sensore

User and Role Management

ComandoDescrizione
GET /api/v3.3/usersElenca utenti
POST /api/v3.3/usersCrea utente
GET /api/v3.3/users/{id}Ottieni dettagli utente
PATCH /api/v3.3/users/{id}Aggiorna utente
DELETE /api/v3.3/users/{id}Elimina utente

Alert Management

ComandoDescrizione
GET /api/v3.3/alertsElenco avvisi
POST /api/v3.3/alertsCrea regola di avviso
GET /api/v3.3/alerts/{id}Ottieni dettagli alert
PATCH /api/v3.3/alerts/{id}Aggiorna regola di avviso
DELETE /api/v3.3/alerts/{id}Elimina regola di avviso

Integration Management

ComandoDescrizione
GET /api/v3.3/integrationsElenco integrazioni
POST /api/v3.3/integrationsCreare integrazione
GET /api/v3.3/integrations/{id}Ottieni dettagli di integrazione
PATCH /api/v3.3/integrations/{id}Aggiornamento integrazione
DELETE /api/v3.3/integrations/{id}Elimina integrazione

Data Export

ComandoDescrizione
vectra-cli export detections --format jsonEsporta rilevamenti
vectra-cli export hosts --format csvEsporta host
vectra-cli export accounts --format jsonEsporta account
vectra-cli export --start-date 2025-01-01Esporta con filtro data
vectra-cli export --threat-score-min 50Esporta con filtro del punteggio

Monitoring and Health

ComandoDescrizione
GET /api/v3.3/healthControlla l’integrità della piattaforma
GET /api/v3.3/system/statusOttieni stato del sistema
GET /api/v3.3/sensors/healthControlla lo stato di salute del sensore
GET /api/v3.3/system/metricsOttieni metriche di sistema
GET /api/v3.3/system/logsOttieni log di sistema

Advanced Queries

ComandoDescrizione
GET /api/v3.3/detections?detection_type=command_and_controlFiltra per tipo di rilevamento
GET /api/v3.3/detections?src_ip=192.168.1.100Filtra per IP sorgente
GET /api/v3.3/detections?dst_port=443Filtra per porta di destinazione
GET /api/v3.3/hosts?last_detection_timestamp_gte=2025-01-01Filtra per timestamp

Bulk Operations

ComandoDescrizione
vectra-cli bulk assign --detections <file>Assegnazione bulk delle rilevazioni
vectra-cli bulk update --hosts <file>Aggiornamento bulk degli host
vectra-cli bulk export --query <query>Esportazione in blocco con query
vectra-cli bulk remediate --actions <file>Azioni di bonifica in massa

Automation and Scripting

ComandoDescrizione
vectra-cli script run --file <script>Esegui script di automazione
vectra-cli script validate --file <script>Convalidare script
vectra-cli workflow create --name <name>Crea workflow
vectra-cli workflow run --id <workflow-id>Esegui workflow

Performance Optimization

ComandoDescrizione
vectra-cli optimize --cache-size 1GBImposta dimensione cache
vectra-cli optimize --parallel 10Imposta elaborazione parallela
vectra-cli optimize --timeout 300Imposta timeout
vectra-cli cache clearCancella cache
vectra-cli cache statusControlla stato cache

Debugging and Troubleshooting

ComandoDescrizione
vectra-cli debug --log-level debugAbilita registrazione debug
vectra-cli debug connectivityVerifica connettività
vectra-cli debug api --endpoint <endpoint>Endpoint di test API
vectra-cli debug permissionsControlla permessi
vectra-cli logs --tail 100Visualizza log recenti

Environment Variables

VariabileDescrizione
VECTRA_TOKENToken di autenticazione API
VECTRA_URLURL della Piattaforma
VECTRA_TIMEOUTTimeout della richiesta
VECTRA_LOG_LEVELLivello di logging
VECTRA_CACHE_DIRDirectory di cache

Configuration Files

FileDescrizione
vectra.config.jsonFile di configurazione principale
vectra-rules.ymlRegole di rilevamento
vectra-integrations.ymlImpostazioni di integrazione
.vectra-credentialsCredenziali memorizzate

Common Detection Types

TipoDescrizione
command_and_controlComunicazione C2
lateral_movementAttività di movimento laterale
data_exfiltrationTentativi di esfiltrazione di dati
reconnaissanceRicognizione di rete
privilege_escalationEscalation dei privilegi