/
KillProcessWrapper.yml
73 lines (73 loc) · 2.24 KB
/
KillProcessWrapper.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
args:
- default: false
description: The Endpoint ID in which you would like to kill the given process.
isArray: false
name: endpoint_id
required: true
secret: false
- default: false
description: The ID of the process to kill. Either the process_id or the process_name must
be specified.
isArray: false
name: process_id
required: false
secret: false
- default: false
description: The name of the process to kill. Either the process_id or the process_name
must be specified.
isArray: false
name: process_name
required: false
secret: false
- auto: PREDEFINED
default: false
description: Are you sure you want to kill this process?
isArray: false
name: approve_action
predefined:
- 'YES'
- 'NO'
required: true
secret: false
comment: 'A cross-vendor wrapper script that triggers a ‘process kill’ command - i.e
executes the proper kill process command according to the vendor: CrowdstrikeFalcon
or Cortex XDR. The script will only fail when the kill process action fails for both vendors.'
commonfields:
id: KillProcessWrapper
version: -1
enabled: false
name: KillProcessWrapper
outputs:
- contextPath: CrowdStrike.Command.kill
description: The outputs of the CrowdStrike kill process command.
type: List
- contextPath: CrowdStrike.Command.kill.Error
description: The status of the CrowdStrike kill process command.
type: String
- contextPath: CrowdStrike.Command.kill.HostID
description: The endpoint ID of the process.
type: String
- contextPath: CrowdStrike.Command.kill.ProcessID
description: The ID of the process.
type: String
- contextPath: PaloAltoNetworksXDR.ScriptRun
description: The outputs of the Cortex XDR kill process command.
type: List
- contextPath: PaloAltoNetworksXDR.ScriptRun.action_id
description: The ID of the kill process action initiated.
type: Number
- contextPath: PaloAltoNetworksXDR.ScriptRun.endpoints_count
description: The number of endpoints the action was initiated on.
type: Number
- contextPath: PaloAltoNetworksXDR.ScriptRun.status
description: The status of the kill process action.
type: Number
script: '-'
subtype: python3
system: false
timeout: '0'
type: python
dockerimage: demisto/python3:3.10.10.48392
tests:
- No tests (auto formatted)
fromversion: 6.1.0