Isolate Endpoint - Generic
Common Playbooks Pack.#
This Playbook is part of theDeprecated
Use the "Isolate Endpoint - Generic V2" playbook instead.
Isolates a given endpoint using the following integrations:
- Carbon Black Enterprise Response
- Palo Alto Networks Traps
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooks- Block Endpoint - Carbon Black Response
- Traps Isolate Endpoint
- Isolate Endpoint - Cybereason
#
IntegrationsThis playbook does not use any integrations.
#
ScriptsThis playbook does not use any scripts.
#
CommandsThis playbook does not use any commands.
#
Playbook InputsName | Description | Required |
---|---|---|
Hostname | The hostname of the endpoint to block. | Optional |
EndpointId | The Endpoint ID to isolate using Traps. | Optional |
#
Playbook OutputsPath | Description | Type |
---|---|---|
CbResponse.Sensors.CbSensorID | The Carbon Black Response Sensors IDs that has been isolated. | string |
Endpoint | The isolated Endpoint. | string |
Traps.Isolate.EndpointID | The ID of the Endpoint. | string |
Traps.IsolateResult.Status | The status of the isolation operation. | string |