Supported Cortex XSOAR versions: 6.6.0 and later.
This playbook handles all the recovery actions available with Cortex XSIAM, including the following tasks:
- Unisolate endpoint
- Restore quarantined file
Note: The playbook inputs enable manipulating the execution flow; read the input descriptions for details.
This playbook uses the following sub-playbooks, integrations, and scripts.
This playbook does not use any sub-playbooks.
This playbook does not use any integrations.
This playbook does not use any scripts.
|unIsolateEndpoint||Set to True to cancel the endpoint isolation.||True||Optional|
|releaseFile||Set to True to release the quarantined file.||False||Optional|
|endpointID||The endpoint ID.||Optional|
|FileHash||The file hash.||Optional|
There are no outputs for this playbook.