Isolate Endpoint - Generic
Deprecated. Use the "Isolate Endpoint - Generic V2" playbook instead.
- Pack
- CommonPlaybooks
- Tasks
- 6
Inputs
- Hostname — Hostname of the endpoint for isolation.
- EndpointId — Endpoint ID to isolate using Traps.
- xdr_endpoint_id — The endpoint ID (string) to isolate using Cortex XDR. You can retrieve the string from the xdr-get-endpoints command.
- IP — IP address of the endpoint for isolation.
Outputs
- CbResponse.Sensors.CbSensorID — Carbon Black Response Sensors ids that has been isolated.
- Endpoint — The isolated enpoint.
- Traps.Isolate.EndpointID — The ID of the endpoint.
- Traps.IsolateResult.Status — The status of the isolation operation.
- Cybereason.Machine — Cybereason Machine name.
- Cybereason.IsIsolated — Is the machine isolated.
- Endpoint.Hostname — Hostname of the endpoint.
- PaloAltoNetworksXDR.Endpoint.endpoint_id — The endpoint ID.
- PaloAltoNetworksXDR.Endpoint.endpoint_name — The endpoint name.
- PaloAltoNetworksXDR.Endpoint.endpoint_status — The status of the endpoint.
- PaloAltoNetworksXDR.Endpoint.ip — The endpoint's IP addresses.
- PaloAltoNetworksXDR.Endpoint.is_isolated — Whether the endpoint is isolated.
- CbResponse.Sensors.Status — Sensor status.
- CbResponse.Sensors.Isolated — Is sensor isolated.