Recovery Plan
#
This Playbook is part of the Common Playbooks Pack.Supported versions
Supported Cortex XSOAR versions: 6.6.0 and later.
This playbook handles all the recovery actions available with Cortex XSIAM, including the following tasks:
- Unisolate endpoint
- Restore quarantined file
Note: The playbook inputs enable manipulating the execution flow; read the input descriptions for details.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
IntegrationsThis playbook does not use any integrations.
#
ScriptsThis playbook does not use any scripts.
#
Commands- core-unisolate-endpoint
- core-restore-file
#
Playbook InputsName | Description | Default Value | Required |
---|---|---|---|
unIsolateEndpoint | Set to True to cancel the endpoint isolation. | True | Optional |
releaseFile | Set to True to release the quarantined file. | False | Optional |
endpointID | The endpoint ID. | Optional | |
FileHash | The file hash. | Optional |
#
Playbook OutputsThere are no outputs for this playbook.