
Microsoft Defender for Endpoint GCC - Block IOC
Details
This workflow appears in the pivot menu and allows a user to block an indicator of compromise (IOC) in Microsoft Defender for Endpoint GCC.
Description
This workflow appears in the pivot menu and allows a user to block an indicator of compromise (IOC) in Microsoft Defender for Endpoint GCC. Supported observables include: domain, IP address, MD5, SHA1, SHA256, URL.
Target: Microsoft Defender for Endpoint GCC integration target
Steps:
- Check which observable type was provided:
- If the observable type is supported, set the matching local variable
- If not supported, return an error
- Request the IOC be blocked
Required targets
This workflow requires the following targets to be available before it can be run.
Integration targets
- Microsoft Defender for Endpoint GCC
About
- Author
- Cisco
- Version
- v1.0
- Intent
- Pivot Menu
- Integration
- Average rating
- No ratings yet
- Authorship
- Cisco Managed
Contact and support information
External links
Related workflows
Cisco Managed
This workflow appears in the pivot menu and allows a user to isolate a machine in Microsoft Defender for Endpoint GCC.
Cisco Managed
This workflow appears in the pivot menu and allows a user to release a machine from isolation in Microsoft Defender for Endpoint GCC.
Cisco Managed
This workflow appears in the pivot menu and allows a user to unblock an indicator of compromise (IOC) in Microsoft Defender for Endpoint GCC.