Isolate Endpoint - Generic V2
This playbook isolates a given endpoint using various endpoint product integrations. Make sure to provide valid playbook inputs for the integration you are using.
- Pack
- CommonPlaybooks
- Tasks
- 8
Inputs
- Endpoint_hostname — The host name of the endpoint to isolate.
- Endpoint_ip — The IP of the endpoint to isolate.
- Endpoint_id — The ID of the endpoint to isolate.
Outputs
- CbResponse.Sensors.CbSensorID — Carbon Black Response Sensor IDs that were isolated.
- Endpoint — The isolated endpoint.
- Traps.Isolate.EndpointID — The ID of the endpoint.
- Traps.IsolateResult.Status — The status of the isolation operation.
- Cybereason.Machine — The Cybereason machine name.
- Cybereason.IsIsolated — Whether the machine is isolated.
- Endpoint.Hostname — The host name of the endpoint.
- PaloAltoNetworksXDR.Endpoint.endpoint_id — The endpoint ID.
- PaloAltoNetworksXDR.Endpoint.endpoint_name — The endpoint name.
- PaloAltoNetworksXDR.Endpoint.endpoint_status — The status of the endpoint.
- PaloAltoNetworksXDR.Endpoint.ip — The endpoint's IP address.
- PaloAltoNetworksXDR.Endpoint.is_isolated — Whether the endpoint is isolated.
- CbResponse.Sensors.Status — The sensor status.
- CbResponse.Sensors.Isolated — Whether the sensor is isolated.
- MicrosoftATP.MachineAction.ID — The machine action ID.
- MicrosoftATP.IsolateList — The IDs of the machines that were isolated.
- MicrosoftATP.NonIsolateList — The IDs of the machines that will not be isolated.
- MicrosoftATP.IncorrectIDs — Incorrect device IDs entered.
- MicrosoftATP.IncorrectHostnames — Incorrect device host names entered.
- MicrosoftATP.IncorrectIPs — Incorrect device IPs entered.