Skip to main content
Executes a RTR active-responder command on the given host. Note that an active session for the host is required - you can use the Create Batch Session action for the wanted host. Use this endpoint to run these real time response commands:
  • cat
  • cd
  • clear
  • cp
  • encrypt
  • env
  • eventlog
  • filehash
  • get
  • getsid
  • help
  • history
  • ipconfig
  • kill
  • ls
  • map
  • memdump
  • mkdir
  • mount
  • mv
  • netstat
  • ps
  • reg query
  • reg set
  • reg delete
  • reg load
  • reg unload
  • restart
  • rm
  • runscript
  • shutdown
  • unmap
  • update history
  • update install
  • update list
  • update query
  • xmemdump
  • zip
External DocumentationTo learn more, visit the CrowdStrike documentation.

Parameters

Example Output

Workflow Library Example

Run Command on a Single Host with Crowdstrike and Send Results Via Email
Workflow LibraryPreview this Workflow on desktop