Responders (8)
Trigger automated responses
PaloAltoCortexXDR isolate v1.0
Isolate endpoints identified by hostname or IP list
- Author: Joe Lazaro
- License: AGPL-V3
- Data Types:
thehive:case_artifact
PaloAltoCortexXDR unisolate v1.0
Unisolate endpoints identified by hostname or IP list
- Author: Joe Lazaro
- License: AGPL-V3
- Data Types:
thehive:case_artifact
PaloAltoCortexXDR scan v1.0
Scan endpoints identified by hostname or IP list
- Author: Joe Lazaro
- License: AGPL-V3
- Data Types:
thehive:case_artifact
PaloAltoCortexXDR restore file v1.0
Restore a quarantined file on all endpoints where it was quarantined, identified by its SHA256 hash
- Author: Joe Lazaro; Fabien Bloume, StrangeBee
- License: AGPL-V3
- Data Types:
thehive:case_artifact
PaloAltoCortexXDR cancel scan v1.0
Cancel a running scan on endpoints identified by hostname or IP list
- Author: Joe Lazaro; Fabien Bloume, StrangeBee
- License: AGPL-V3
- Data Types:
thehive:case_artifact
PaloAltoCortexXDR allow list v1.0
Add a file hash to the Cortex XDR allow list
- Author: Joe Lazaro; Fabien Bloume, StrangeBee
- License: AGPL-V3
- Data Types:
thehive:case_artifact
PaloAltoCortexXDR block list v1.0
Add a file hash to the Cortex XDR block list
- Author: Joe Lazaro; Fabien Bloume, StrangeBee
- License: AGPL-V3
- Data Types:
thehive:case_artifact
PaloAltoCortexXDR initiate forensics v1.0
Initiate forensics triage collection on endpoints identified by hostname or IP list
- Author: Joe Lazaro; Fabien Bloume, StrangeBee
- License: AGPL-V3
- Data Types:
thehive:case_artifact




































