Skip to main content

Cortex XDR - Isolate Endpoint

This playbook accepts an XDR endpoint ID and isolates it using the 'Palo Alto Networks Cortex XDR - Investigation and Response' integration.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

GenericPolling

Integrations#

CortexXDRIR

Scripts#

This playbook does not use any scripts.

Commands#

  • xdr-get-endpoints
  • xdr-isolate-endpoint

Playbook Inputs#


NameDescriptionDefault ValueRequired
endpoint_idThe endpoint ID (string) to isolate. You can retrieve the ID using the xdr-get-endpoints command.PaloAltoNetworksXDR.Endpoint.endpoint_idOptional
hostnameA comma-separated list of hostnames.Endpoint.HostnameOptional
ip_listA comma-separated list of IP addresses.IP.AddressOptional

Playbook Outputs#


PathDescriptionType
PaloAltoNetworksXDR.Endpoint.endpoint_idThe endpoint ID.unknown
PaloAltoNetworksXDR.Endpoint.endpoint_nameThe endpoint name.unknown
PaloAltoNetworksXDR.Endpoint.endpoint_statusThe status of the endpoint.unknown
PaloAltoNetworksXDR.Endpoint.ipA list of IP addresses.unknown
PaloAltoNetworksXDR.Endpoint.is_isolatedWhether the endpoint is isolated.unknown
Endpoint.HostnameThe hostname that is mapped to this endpoint.unknown

Playbook Image#


Cortex XDR - Isolate Endpoint