On an Endpoint Security (HX) appliance, roles have associated capabilities. The functionality provided by each capability and the roles authorized to perform each capability are described in the following table.
In general, if a user is assigned an AAA role that has Web UI access, the actions they can perform occur mostly in the Web UI. In the CLI, only the show commands are available for these roles. The exceptions to this are the admin role (which can perform all available functions in the CLI) and the operator role (which can perform HX appliance software maintenance functions in the CLI, but cannot run CLI commands related to HX Series configuration settings).
If a user is assigned an AAA role that has API access, the actions they can perform occur only in the API. The only exception to this is the fe_services user, who can perform all available functions in the CLI and API, but has no access to the Web UI.
Capability | Description | Authorized AAA roles |
|---|---|---|
Web UI Access | Access the Web UI. Users with auditor roles have access to logs only. Users with monitor roles have access to the Appliance Settings and Health Check, and are able to view Appliance Updates only. | admin analyst analyst_sr auditor investigator monitor operator |
API Access | Access the API | api_admin api_analyst fe_services |
CLI Access | Access the CLI | admin (full access) analyst ( analyst_sr ( auditor ( fe_services (full access) investigator ( monitor ( operator (appliance image management, |
FireEye as a Service (FaaS) | Manage services | fe_services |
Acquisitions (view) | View acquisitions | admin analyst analyst_sr api_admin api_analyst fe_services investigator |
Agent Clone | Manage cloned agents | admin |
Agent Clone (view) | View cloned agents | admin analyst analyst_sr api_admin api_analyst fe_services investigator operator |
Agent Configurations | Manage agent configuration settings and deploy them to the agents | admin (Web UI) api_admin (API) operator (Web UI partial) |
Agent Diagnostics | Perform agent diagnostics | admin fe_services |
Agent Diagnostics (view) | View agent diagnostics | admin fe_services |
Alerts | Manage and view alerts | admin analyst analyst_sr api_admin api_analyst fe_services investigator |
Approve Containment | Approve containment requests and stop containment of host endpoints | admin api_admin fe_services investigator |
Audit Viewer | Request and view audit data. In the Web UI, this includes processing acquisition data and reviewing it in the Audit Viewer, In the API, this involves searching for audit data in acquisitions using a script. | admin analyst analyst_sr api_admin api_analyst fe_services investigator |
Authentication (AAA) | Maintain authorization settings for user accounts | admin fe_services |
Authentication (AAA) (view) | View authorization settings for user accounts | admin monitor operator |
Dashboard | Select links on the Web UI dashboard | admin analyst analyst_sr investigator |
Dashboard (view) | View the Web UI dashboard | admin analyst analyst_sr investigator operator |
Data Acquisitions (Live Response) | Request data acquisitions | admin analyst analyst_sr api_admin api_analyst fe_services investigator |
Enterprise Search | Run enterprise searches | admin analyst analyst_sr api_admin api_analyst fe_services investigator |
File Acquisitions | Request file acquisitions | admin analyst_sr api_admin api_analyst fe_services investigator |
Health Check View | Review system health | admin analyst analyst_sr fe_services investigator monitor operator |
Hosts | Maintain host lists | admin analyst analyst_sr api_admin api_analyst fe_services investigator |
Hosts (view) | View host lists | admin analyst analyst_sr api_admin api_analyst fe_services investigator operator |
Host Sets | Maintain host sets | admin operator |
Host Sets (view) | View host sets | admin analyst analyst_sr api_admin api_analyst fe_services investigator operator |
Indicator | Maintain and view indicators and custom indicators | admin analyst analyst_sr api_admin api_analyst fe_services investigator |
Module Administration | Install, uninstall, enable, disable, and upgrade modules | admin api_admin investigator |
Module Data | View module data pages | all roles |
Appliance Licenses | Maintain appliance licenses | admin fe_services operator |
Appliance Licenses (view) | View appliance licenses | admin fe_services monitor operator |
Logs | View logs and customize log settings | admin auditor fe_services operator |
Manage Own Account | Change the password for the specific user account | admin analyst analyst_sr auditor investigator monitor operator |
Network | Maintain network settings | admin operator |
Network (View) | View network settings | admin fe_services monitor operator |
PKI | Import and export HX certificates for the agent population | admin |
Stats | Manage statistics | admin operator |
Stats (view) | View statistics | admin fe_services monitor operator |
Appliance Settings (general) | Perform general system administration functions for the appliance (but not sensitive functions). These include setting the date and time, modifying DTI network settings, managing notifications, modifying network settings, changing certificates and keys, managing appliance licenses, and changing the login banner. | admin operator |
Appliance Settings (view) | View appliance settings. | admin fe_services monitor operator |
Appliance Settings (sensitive) | Perform general and sensitive administrative functions for the appliance. These include managing user accounts (AAA) and appliance backup and restore functionality. | admin fe_services |
System Diagnostics | Perform system diagnostics | admin operator |