Block Endpoint - Carbon Black Response

Isolates an endpoint and a given hostname.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

  • carbonblack

Scripts#

This playbook does not use any scripts.

Commands#

  • cb-sensor-info
  • cb-quarantine-device

Playbook Inputs#


NameDescriptionDefault ValueRequired
HostnameThe hostname to isolate.${Endpoint.Hostname}Optional

Playbook Outputs#


PathDescriptionType
CbResponse.Sensors.CbSensorIDThe Carbon Black Response Sensors IDs that has been isolated.unknown
EndpointThe isolated enpoint.unknown

Playbook Image#


Block_Endpoint_Carbon_Black_Response