Skip to main content

CyberArk Deactivate EPM SOC Response

This Playbook is part of the CyberArk Endpoint Privilege Manager Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.10.0 and later.

Deactivates a specific CyberArk EPM SOC risk plan for a specific endpoint. This reverts all security settings to the baseline EPM policies active prior to the SOC response action.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

This playbook does not use any integrations.

Scripts#

  • IsIntegrationAvailable

Commands#

  • cyberarkepm-deactivate-risk-plan

Playbook Inputs#


NameDescriptionDefault ValueRequired
endpoint_nameThe FQDN of the target endpoint.Required
endpoint_external_ipThe external IP of the target endpoint.Required
risk_planThe name of the risk plan to remove (Medium_Risk_Plan or High_Risk_Plan).Required

Playbook Outputs#


There are no outputs for this playbook.

Playbook Image#


CyberArk Deactivate EPM SOC Response