Playbook WF: Delete File on Host with Orbital Script via Prompt
This Playbook Task workflow uses the "Delete a File" catalog script in Cisco Orbital. It supports Windows, Linux, and macOS. An XDR automation prompt task is used to request which file to delete from the selected devices.
Description
This Playbook Task workflow uses the Delete a File catalog script in Cisco Orbital. It supports Windows, Linux, and macOS. An XDR automation prompt task is used to request which file to delete from the selected devices.
Please make sure to enter the full path for the file to delete (e.g. C:\Windows\notepadz.exe
). The result of the Orbital job will be sent via the Incident Worklog.
Note: This workflow will not delete files in system folders.
Target: Orbital - v0
Steps:
- Create a prompt asking which file to delete from the selected devices.
- Loop through all observables and run the Orbital script for each Hostname.
- Check if the script execution was successful (if not, update the Workflow Results for the Worklog).
This workflow requires the following targets to be available before it can be run.
Integration targets
- Orbital