Block File - Generic v2
Common Playbooks Pack.#
This Playbook is part of theThis playbook is used to block files from running on endpoints. This playbook supports the following integrations:
- Palo Alto Networks Traps
- Palo Alto Networks Cortex XDR
- Cybereason
- Carbon Black Enterprise Response
- Cylance Protect v2
- Crowdstrike Falcon
- Microsoft Defender for Endpoint.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooks- Cortex XDR - Block File
- Block File - Carbon Black Response
- MDE - Block File
- Block File - Cylance Protect v2
- Block File - Cybereason
- CrowdStrike Falcon - Block File
#
IntegrationsThis playbook does not use any integrations.
#
ScriptsThis playbook does not use any scripts.
#
CommandsThis playbook does not use any commands.
#
Playbook InputsName | Description | Default Value | Required |
---|---|---|---|
MD5 | The MD5 hash of the file you want to block. | File.MD5 | Optional |
SHA256 | The SHA256 hash of the file you want to block. | File.SHA256 | Optional |
Hash | In this input you can insert either MD5 or SHA256 that you wish to block. | Optional |
#
Playbook OutputsPath | Description | Type |
---|---|---|
CbResponse.BlockedHashes.LastBlock.Time | Last block time. | unknown |
CbResponse.BlockedHashes.LastBlock.Hostname | Last block hostname. | unknown |
CbResponse.BlockedHashes.LastBlock.CbSensorID | Last block sensor ID. | unknown |