AS-MDE-Isolate-Machine

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This playbook is intended to be run from a Microsoft Sentinel Incident. It will match Microsoft Defender for Endpoint machines with the host entities on the incident and then isolate them.

Attribute Value
Type Playbook
Solution Standalone Content
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Playbooks