Skip to main content

Block Endpoint - Carbon Black Response

This Playbook is part of the Carbon Black Enterprise Response Pack.#

Carbon Black Response isolates an endpoint for a given hostname.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

carbonblack

Scripts#

This playbook does not use any scripts.

Commands#

  • cb-quarantine-device
  • cb-sensor-info

Playbook Inputs#


NameDescriptionDefault ValueRequired
HostnameThe hostname to isolate.${Endpoint.Hostname}Optional

Playbook Outputs#


PathDescriptionType
CbResponse.Sensors.CbSensorIDCarbon Black Response Sensors IDs that are isolated.unknown
EndpointThe isolated enpoint.unknown
CbResponse.Sensors.StatusSensor status.unknown
CbResponse.Sensors.IsolatedIs sensor isolated.unknown
Endpoint.HostnameEndpoint hostname.unknown

Playbook Image#


Block Endpoint - Carbon Black Response