Delete File on Host with Orbital Script via Prompt
This pivot menu workflow uses the "Delete a File" catalog script in Cisco Orbital. It supports Windows, Linux, and macOS. An XDR automation prompt task is used to request which file to delete from the user who runs the workflow.
Description
This pivot menu workflow uses the Delete a File catalog script in Cisco Orbital. It supports Windows, Linux, and macOS. An XDR automation prompt task is used to request which file to delete from the user who runs the workflow.
Please make sure to enter the full path for the file to delete (e.g. C:\Windows\notepadz.exe
). The result of the Orbital job will be sent via a notification.
Note: This workflow will not delete files in system folders.
Target: Orbital - v0
Steps:
- Create a prompt asking which file to delete
- Determine which observable we're using to identify the endpoint
- Run the Orbital script
- Check if the script execution was successful (if not, end the workflow)
- Let the user know the script was executed
This workflow requires the following targets to be available before it can be run.
Integration targets
- Orbital
- Cisco XDR