Details

This Playbook Task workflow uses the "Delete a File" catalog script in Cisco Orbital. It supports Windows, Linux, and macOS. An XDR automation prompt task is used to request which file to delete from the selected devices.

Description

This Playbook Task workflow uses the Delete a File catalog script in Cisco Orbital. It supports Windows, Linux, and macOS. An XDR automation prompt task is used to request which file to delete from the selected devices.

Please make sure to enter the full path for the file to delete (e.g. C:\Windows\notepadz.exe). The result of the Orbital job will be sent via the Incident Worklog.

Note: This workflow will not delete files in system folders.

Target: Orbital - v0

Steps:

  1. Create a prompt asking which file to delete from the selected devices.
  2. Loop through all observables and run the Orbital script for each Hostname.
  3. Check if the script execution was successful (if not, update the Workflow Results for the Worklog).
Required targets

This workflow requires the following targets to be available before it can be run.

Integration targets

  • Orbital
About
Author
Christopher van der Made
Version
v1.0
Intent
Playbook Task
Integration
Average rating
No ratings yet
Authorship
Community
Contact and support information
External links
Related workflows
Cisco Managed
This workflow works with an incident automation rule or playbook task to execute an Orbital query on an XDR incident's assets.
Cisco Managed
This workflow works with an incident response playbook to execute an Orbital query on user-selected assets from an XDR incident.
Cisco Managed
This workflow works with an incident automation rule or playbook task to execute an Orbital script on an XDR incident's assets.
Cisco Managed
This workflow works with an incident response playbook to execute an Orbital script on user-selected assets from an XDR incident.
Community
This incident response workflow consumes one or more users (user or process_username) and attempts to disable the local account on endpoints running windows, mac or linux.
Community
This incident response workflow consumes one or more users (user or process_username) and attempts to force a logout from endpoints running windows, mac or linux.
Community
This incident response workflow consumes one or more users (user or process_username) and attempts to re-enable the local account on endpoints running windows, mac or linux This workflow is intended for use in a playbook during the recovery stage.
Cisco Managed
This workflow initiates a Cisco Orbital forensic snapshot for the endpoint identified by the provided observable.