Actions
Perform Host Action
Perform various actions on the hosts in your environment.
Basic Parameters
Parameter | Description |
---|---|
Action Name | Specify one of these actions:- contain - This action contains the host, which stops any network communications to locations other than the CrowdStrike cloud and IPs specified in your Containment Policy. |
lift_containment
- This action lifts containment on the host, which returns its network communications to normal.hide_host
- This action will delete a host. After the host is deleted, no new detections for that host will be reported via UI or APIs.unhide_host
- This action will restore a host. Detection reporting will resume after the host is restored. | | Host IDs | A comma-separated list of host IDs to perform the action on. Can be obtained via theList Devices
action. |
Advanced Parameters
Parameter | Description |
---|---|
Action Parameters | A comma-separated list of the parameters for the prospective action.Example value: {“name”: “name1”, “value”: “value1”}, {“name”: “name2”, “value”: “value2”} |
Example Output
Workflow Library Example
Isolate or Unisolate Device on Crowdstrike
Preview this Workflow on desktop
Was this page helpful?