Skip to main content

Autonomous Response Actions (supported tools)

  1. Isolate Host - Crowdstrike, SentinelOne, Microsoft, Watchguard, Aurora, TrendAI
  2. Lift Host Containment - Crowdstrike, SentinelOne, Microsoft, Watchguard, TrendAI
  3. Blocklist File - Crowdstrike, SentinelOne, TrendAI
  4. Kill Process - SentinelOne
  5. Quarantine File - SentinelOne, Microsoft, Watchguard, Aurora
  6. Email Automations - Sublime, Mimecast
  7. Revoke Session - Microsoft Entra
  8. Disable User - Microsoft Entra
  9. Enable User - Microsoft Entra
  10. Automatic Ticket Creation - Jira, ServiceNow, PagerDuty, SolarWinds, Freshdesk, Zendesk, HaloPSA

Automated Response Configuration

Each response action includes three possible configuration states:
  1. Automated - Response action is performed at the time the case is created
  2. Analyst Approved - Analysts can manually perform the action in the platform by clicking Resolve
  3. Approval Required - Red tag next to the response action notifying the analyst that they need to request approval from the end customer