Is there a Query to see the BIOS version with Cortex XDR Pro?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Is there a Query to see the BIOS version with Cortex XDR Pro?

L2 Linker

Looking for a query to see the BIOS version in Cortex XDR, if there is a variable to show it. We have XDR Pro with host insights.

Cortex XDR 

1 REPLY 1

L5 Sessionator

Hi J.Suter, 

Even though you have the Host Insights, BIOS version is not retrieved by this add-on. 

 

You have other options from the Cortex XDR tenant. 

 

  1. Right click on the endpoint you want to retrieve the bios version from. Select EndPoint Control ---> Open in interactive mode, then scroll down to select "execute_commands HIGH RISK" and give the following command:
    wmic bios get smbiosbiosversion. You will get the BIOS version of your endpoint.
  2. Bulk operation: From the all endpoints table, You can filter as you wish as many endpoints as you want, select all of them and shoot the former command in the same way as in point 1
  3. Bulk operation from the Action Center: You can create a script with the former command (point 1). Then you can select to execute script in as many endpoints as you want. You will get a table as a result that you can later export to excel file and then merge with other data in excel or even loading as a lookup dataset to XQL query it later on. 

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.

 

KR,

Luis

 

  • 270 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!