Response actions

What a playbook or an analyst can do, and which connector each action needs.

On the endpoint, through the agent

ActionNotes
Isolate hostChoose the containment mode. See Network isolation.
Release hostRestores the previous firewall state.
Kill processBy process identifier.
Block applicationBy image name or hash. See Application control.
Collect fileInto case evidence.
Collect triage packageSee Quick triage.

In other systems, through connectors

ActionConnectorStatus
Disable user, revoke sessionsOktaLive
Disable userMicrosoft Entra IDLive
Block IP at the firewallFortiGateLive
Quarantine email (move to Junk or soft-delete)Microsoft 365Live
Isolate device in the EDRMicrosoft Defender for EndpointComing soon

Each action needs the connector configured with a credential that has the corresponding permission. Configure write permissions only for actions you intend to use; the integration panel shows which actions a connector's credential allows.

Governance

Every execution, automatic or confirmed, is attributed to a run and an identity and lands in the audit trail. Deterministic run identifiers prevent an action from firing twice for the same alert. Staged actions expire if not confirmed within the time set in Settings › AI.