Search:

Invoke-ComaeAzVMWinAnalyze

Invoke-ComaeAzVMWinAnalyze

Synopsis

Invoke DumpIt on a remote Windows Azure Virtual Machine, and send it to the Comae platform.

Syntax

Invoke-ComaeAzVMWinAnalyze [-Token] <String> [-OrganizationId] <String> [-CaseId] <String> [-ResourceGroupName] 
<String> [-VMName] <String> [[-Hostname] <String>] [<CommonParameters>]

Parameters

NameAliasDescriptionRequired?Pipeline InputDefault Value
TokenBearer token generated by the user on via the user interface of the Comae platform.truefalse
OrganizationIdThe organization id can be retrieved in the user interface or by calling Get-ComaeOrganizations.truefalse
CaseIdThe case id can be retrieved in the user interface or by calling Get-ComaeCases.truefalse
ResourceGroupNameThe resource group name where the Azure virtual machine belongs to.truefalse
VMNameThe name of the Azure virtual machine.truefalse
HostnameDefault hostname is beta.comae.tech but this can be changed for private instances.falsefalsebeta.comae.tech

Examples

EXAMPLE 1 Invoke a run command ‘RunPowerShellScript’ with overriding the script ‘ComaeRespond.ps1’ on a Windows VM named ‘$VMName’ in resource group ‘$rgname’.

PS C:\\\> Invoke-ComaeAzVMWinAnalyze -Token $Token -OrganizationId $OrganizationId -CaseId $CaseId  
-ResourceGroupName $rgname -VMName $VMName