Details

This atomic belongs to the SentinelOne atomic group.

Adds a SHA-1 file hash to the SentinelOne blocklist.

Target: SentinelOne integration target or an HTTP Endpoint for "your-tenant.sentinelone.net" with a path of "/web/api/v2.1"

Account Key: None if using an integration-provided target, API token if using an HTTP endpoint target

Steps:
[] Build the request payload
[] Generate the authorization header
[] Request the hash be blocklisted
[] Check if the API request succeeded:
[]> If it did, extract the results and set the output variable
[]> If it didn't, output an error

More information about this API can be found in the SentinelOne documentation

About
Authorship
Cisco Managed