Details

This atomic belongs to the CrowdStrike atomic group.

Runs a real time response script on an endpoint in CrowdStrike. You will need to start a real time response session before using this atomic. Note that the "runscript" real time response command requires administrative real time response permissions, not read-only permissions.

Target: CrowdStrike integration target or an HTTP Endpoint for "api.crowdstrike.com"

Account Key: None if using an integration-provided target, access token if using an HTTP Endpoint target

Steps:
[] Check if at least one required input was provided (if not, end the workflow)
[] Build the authorization header
[] Build the request payload
[] Execute the command
[] Check if the request was successful:
[]> If it was, extract the cloud request ID and set the output variable
[]> If it wasn't, return an error

More information about this API can be found in the CrowdStrike documentation.

About
Authorship
Cisco Managed