Receives an MD5 hash and adds it to the blacklist in Carbon Black Enterprise Response. Files with that MD5 hash are blocked from execution on the managed endpoints.
If the integration is disabled at the time of running, or if the hash is already on the blacklist, no action is taken on the MD5.
This playbook uses the following sub-playbooks, integrations, and scripts.
This playbook does not use any sub-playbooks.
This playbook does not use any integrations.
This playbook does not use any scripts.
|MD5||The MD5 hash of the file you want to block.||MD5||File||Optional|
|CbResponse.BlockedHashes.LastBlock.Time||The last block time.||unknown|
|CbResponse.BlockedHashes.LastBlock.Hostname||The last block hostname.||unknown|
|CbResponse.BlockedHashes.LastBlock.CbSensorID||The last block sensor ID.||unknown|