Block File - Generic v2
This playbook is used to block files from running on endpoints. This playbook supports the following integrations: - Palo Alto Networks Traps - Palo Alto Networks Cortex XDR - Cybereason - Carbon Black Enterprise Response - Cylance Protect v2 - Crowdstrike Falcon - Microsoft Defender for Endpoint.
- Pack
- CommonPlaybooks
- Tasks
- 14
Inputs
- MD5 — The MD5 hash of the file you want to block.
- SHA256 — The SHA256 hash of the file you want to block.
- Hash — In this input you can insert either MD5 or SHA256 that you wish to block.
Outputs
- CbResponse.BlockedHashes.LastBlock.Time — Last block time.
- CbResponse.BlockedHashes.LastBlock.Hostname — Last block hostname.
- CbResponse.BlockedHashes.LastBlock.CbSensorID — Last block sensor ID.