Sysdig Response Actions (v2.0.1)

This is an integration that will use Sysdig agent to respond to malicious activity by triggering different actions at the host or container level like killing a container, quarantine a file or perform a system capture

Author
Sysdig
Support
partner
URL
https://sysdig.com/support/
Default data source
SysdigResponseActions
Categories
Data Enrichment & Threat Intelligence

Incident fields (37)

Integrations (1)

Layouts (1)

README

Sysdig Response Actions

This integration utilizes the Sysdig agent and the Sysdig Response Actions API to facilitate automated and manual remediation of security incidents. It enables security teams to take precise actions at the host or container level, such as terminating compromised containers, quarantining suspicious files, or capturing detailed system activity for forensic analysis. These capabilities are designed to enhance incident response workflows and improve overall security operations.

What does this pack do?

This pack leverages the Sysdig Response Actions API to enable automated and manual responses to security incidents. Key features include:

These capabilities help streamline incident response and enhance security posture.

For more information, visit Sysdig.

Sysdig Overview