Examples of custom collector and reaction scripts
The McAfee MVision EDR platform allows the organisation to essentially trigger arbitrary processes on any endpoint.
This powerful feature means you can essentially do anything you like on a remote endpoint simply by clicking a couple of buttons.
This repository contains a number of examples of how you can leverage this power to achieve various results. A primary feature demonstrated here currently is the ability to pull down any remote tool and execute it to achieve complex outcomes and push results to various external services (such as a McAfee Advanced Threat Defence sandbox, or ATD, and push evidence collected to an FTP site).
- Collections
- Reactions
- Utilities