Recovery Plan
This playbook handles all the recovery actions available with Cortex XSIAM, including the following tasks: * Unisolate endpoint * Restore quarantined file Note: The playbook inputs enable manipulating the execution flow; read the input descriptions for details.
- Pack
- CommonPlaybooks
- Tasks
- 6
Inputs
- unIsolateEndpoint — Set to True to cancel the endpoint isolation.
- releaseFile — Set to True to release the quarantined file.
- endpointID — The endpoint ID.
- FileHash — The file hash.
Commands used
- core-restore-file
- core-unisolate-endpoint