Skip to main content

Block Endpoint - Carbon Black Response

This Playbook is part of the Carbon Black Enterprise Response Pack.#

Deprecated

Use the Block Endpoint - Carbon Black Response V2.1 playbook instead.

Deprecated. Use the Block Endpoint - Carbon Black Response V2.1 playbook instead. Carbon Black Response - isolate an endpoint, given a hostname.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

  • carbonblack

Scripts#

This playbook does not use any scripts.

Commands#

  • cb-quarantine-device
  • cb-sensor-info

Playbook Inputs#


NameDescriptionDefault ValueRequired
HostnameThe hostname to isolate.${Endpoint.Hostname}Optional

Playbook Outputs#


PathDescriptionType
CbResponse.Sensors.CbSensorIDCarbon Black Response sensor IDs that have been isolated.unknown
EndpointThe isolated enpoint.unknown
CbResponse.Sensors.StatusSensor status.unknown
CbResponse.Sensors.IsolatedIs sensor isolated.unknown
Endpoint.HostnameEndpoint hostname.unknown

Playbook Image#


Block Endpoint - Carbon Black Response