
CrowdStrike - Execute Host Actions
Details
This atomic belongs to the CrowdStrike atomic group.
Perform various actions on one or more host in CrowdStrike such as enabling or lifting containment, deleting a host, or restoring a deleted host.
Target: CrowdStrike integration target or an HTTP Endpoint for "api.crowdstrike.com"
Account Key: None if using an integration-provided target, access token if using an HTTP Endpoint target
Steps:
[] Check if a list of IDs was provided (if not, wrap the ID into a list)
[] Build the authorization header
[] Request the host action
[] Check if the API request succeeded:
[]> If it did, set the output variable
[]> If it didn't, output an error
More information about this API can be found in the CrowdStrike documentation.
About
Integration
Authorship
Cisco Managed