🌙
 

Subscribe to the Taegis™ XDR Documentation RSS Feed at .

Learn more about RSS readers or RSS browser extensions.

Endpoint Proactive Response Example Playbook

managedxdr

Important

When configuring playbooks for Proactive Response, the playbook name must match the trigger name and follow the Proactive Response Naming Convention.

Host Isolation and Restoration Playbook Configuration

  1. Configure a Taegis Agent - Isolate playbook for the Isolate action using the trigger parameters shown below. For more information about adding a new playbook, see Create a New Playbook.

Playbook for isolating endpoints with the Taegis Agent installed

Playbook for isolating endpoints with the Taegis Agent installed

Note

Each playbook has built-in documentation that walks through the steps to create a new playbook. Select Documentation from a playbook template or configured playbook in XDR to open this in a new tab and follow the guidance there.

  1. Configure a Taegis Agent - Restore playbook for the Restore action using the trigger parameters shown below. For more information about adding a new playbook, see Create a New Playbook.

Playbook for restoring endpoints with the Taegis Agent installed

Playbook for restoring endpoints with the Taegis Agent installed

Note

Each playbook has built-in documentation that walks through the steps to create a new playbook. Select Documentation from a playbook template or configured playbook in XDR to open this in a new tab and follow the guidance there.

  1. Now that you have created the Isolate and Restore playbooks, they appear in the ACTIONS menu for Taegis Agent assets. For example, MXDR_ISOLATE and MXDR_RESTORE.

Response Actions for the Taegis Agent

Response Actions for the Taegis Agent

 

On this page: