Block Endpoint - Carbon Black Response V2
Deprecated. Use the `Block Endpoint - Carbon Black Response V2.1` playbook instead. Carbon Black Response - isolates an endpoint for a given hostname.
- Pack
- Carbon_Black_Enterprise_Response
- Tasks
- 6
Inputs
- Hostname — The hostname to isolate.
- Sensor_id — The sensor ID of the endpoint.
Outputs
- CbResponse.Sensors.CbSensorID — Carbon Black Response Sensors IDs that are isolated.
- Endpoint — The isolated endpoint.
- CbResponse.Sensors.Status — Sensor status.
- CbResponse.Sensors.Isolated — Is sensor isolated.
- Endpoint.Hostname — Endpoint hostname.
Commands used
- cb-quarantine-device
- cb-sensor-info