Get endpoint details - Generic
Deprecated. Use the `Endpoint Enrichment - Generic v2.1` playbook instead. This playbook uses the generic command !endpoint to retrieve details on a specific endpoint. This command currently supports the following integrations: - Palo Alto Networks Cortex XDR - Investigation and Response. - CrowdStrike Falcon.
- Pack
- CommonPlaybooks
- Tasks
- 17
Inputs
- Endpoint_id — The ID of the endpoint that you want to get details about.
- Endpoint_ip — The IP of the endpoint that you want to get details about.
- Endpoint_hostname — The hostname of the endpoint that you want to get details about.
Outputs
- Endpoint.Hostname — The endpoint's hostname.
- Endpoint.OS — The endpoint's operation system.
- Endpoint.IPAddress — The endpoint's IP address or list of IP addresses.
- Endpoint.ID — The endpoint's ID.
- Endpoint.Status — The endpoint's status.
- Endpoint.IsIsolated — Endpoint isolation status.
- Endpoint.MACAddress — Endpoint MAC address.
- Endpoint.Vendor — The integration name of the endpoint vendor.
Commands used
- endpoint