Block File - Cylance Protect v2
This playbook accepts a SHA256 hash and adds the hash to the Global Quarantine list using the Cylance Protect v2 integration.
- Pack
- Cylance_Protect
- Tasks
- 5
Inputs
- SHA256 — The SHA256 hash of the file to block.
- ListType — The list type to which the threat belongs. Can be "GlobalQuarantine" or "GlobalSafe".
Outputs
- CbResponse.BlockedHashes.LastBlock.Time — Last block time
- CbResponse.BlockedHashes.LastBlock.Hostname — Last block hostname
- CbResponse.BlockedHashes.LastBlock.CbSensorID — Last block sensor ID
Commands used
- cylance-protect-add-hash-to-list