Block Endpoint - Carbon Black Response
Deprecated. Use the `Block Endpoint - Carbon Black Response V2.1` playbook instead. Carbon Black Response - isolate an endpoint, given a hostname.
- Pack
- Carbon_Black_Enterprise_Response
- Tasks
- 6
Inputs
- Hostname — The hostname to isolate.
Outputs
- CbResponse.Sensors.CbSensorID — Carbon Black Response Sensors ids that has been isolated.
- Endpoint — The isolated enpoint.
- CbResponse.Sensors.Status — Sensor status.
- CbResponse.Sensors.Isolated — Is sensor isolated.
- Endpoint.Hostname — Endpoint hostname.
Commands used
- cb-quarantine-device
- cb-sensor-info