Which response action in Cortex XSIAM would be unavailable to a SOC analyst investigating an incident involving a Linux server?
Cortex XSIAM (and XDR) agents provide a wide array of response actions, but these capabilities vary based on the operating system of the endpoint.
File Search and Destroy: This specific automated management action---which allows an administrator to search for a file across multiple endpoints and delete it in one click---is currently supported for Windows and macOS endpoints. It is not a native automated response action for Linux in the same 'Search and Destroy' menu context.
Supported Linux Actions: * Live Terminal (B): Analysts can initiate a remote SSH-like session to Linux endpoints for manual investigation.
Running a Script (C): Analysts can execute Python scripts on Linux endpoints to gather data or perform custom remediation.
Halting Network Access (D): Also known as Endpoint Isolation, this allows the analyst to cut off all network traffic to the Linux server except for the connection to the Cortex console.
Currently there are no comments in this discussion, be the first to comment!