On the endpoint, through the agent
| Action | Notes |
|---|---|
| Isolate host | Choose the containment mode. See Network isolation. |
| Release host | Restores the previous firewall state. |
| Kill process | By process identifier. |
| Block application | By image name or hash. See Application control. |
| Collect file | Into case evidence. |
| Collect triage package | See Quick triage. |
In other systems, through connectors
| Action | Connector | Status |
|---|---|---|
| Disable user, revoke sessions | Okta | Live |
| Disable user | Microsoft Entra ID | Live |
| Block IP at the firewall | FortiGate | Live |
| Quarantine email (move to Junk or soft-delete) | Microsoft 365 | Live |
| Isolate device in the EDR | Microsoft Defender for Endpoint | Coming soon |
Each action needs the connector configured with a credential that has the corresponding permission. Configure write permissions only for actions you intend to use; the integration panel shows which actions a connector's credential allows.
Governance
Every execution, automatic or confirmed, is attributed to a run and an identity and lands in the audit trail. Deterministic run identifiers prevent an action from firing twice for the same alert. Staged actions expire if not confirmed within the time set in Settings › AI.