Skip to main content
Once an alert has been investigated, threat has been identified and a case has been created, the next step is to take action. Blink’s Response capabilities enable teams to execute containment, remediation, and notification actions quickly and easily. Using the Deployment Wizard, teams can configure vendor-specific workflows as response actions. Once configured, these actions are available to analysts directly from relevant cases, alerts, observables, and other Case Management records, allowing them to quickly respond to security threats without leaving the investigation. For example, analysts can use response actions to:
  • Isolate a compromised endpoint.
  • Block a malicious IP address or domain.
  • Disable a compromised user account.
  • Quarantine a malicious file.

Configuring Response Actions

Response actions allow analysts to execute predefined workflows directly from the Cases Interface. You can configure response actions for specific entities, such as cases, alerts, observables, attachments, or tasks, and make them available wherever analysts need to take action.
1

Select the Vendor Source

To configure a response action, open the Deployment Wizard and select the vendor source you want to use and configure it. The response action workflows are deployed as part of that vendor’s pack.The Deployment Wizard provides pre-built response workflows for supported vendor sources. You can also use a custom workflow as a response action.
Note: Once deployed, the response workflows appear in the vendor’s Response pack. Each workflow is named using the format Response Ability - <Vendor Name> - <Response Action>, for example, Response Ability - CrowdStrike - Isolate Endpoint.
2

Select Where the Response Action Is Available

Navigate to Case Management Settings and select the entity where you want the response action to be available.You can configure response actions for the following entities:
  • Cases
  • Alerts
  • Observables
  • Attachments
  • Tasks
Select the entity that best matches where the response action will be used in your investigation and response process.
3

Configure the Response Action

Configure the response action by completing the required fields:
  • Name: Enter a descriptive name that clearly identifies what the response action does.
  • Select Workflow: Select the workflow that should run when the response action is executed. You can select a pre-built response workflow configured through the Deployment Wizard or a custom workflow.
  • Filter by Type (Optional): Restrict the response action to specific record types. If left empty, the response action is available for all record types within the selected entity.
  • Record (Optional): Specify a default value to use when the action is executed without a value provided by the user. Leave this field empty if no default value is required.
4

Execute the Response Action

Once configured, the response action is available to analysts from multiple locations in Case Management.
  1. From the Entity Table
    1. Open the table for the entity where you configured the response action, such as Cases.
    2. Select the icon and enable the Action column.
    3. Save the view.
    1. Find the specific record you want to take action on, such as a case, alert, or observable.
    2. In the Action column, select the configured response action to execute it.
  2. From the Case Overview: You can also execute response actions directly from the Case Overview.
    1. In the top-right corner of the Case Overview, select the Action button, select the response workflow you want to run, provide any required parameters and proceed by executing it.
  3. Using Agent Blink: You can also use Agent Blink via the Chat Interface to identify and execute an appropriate response action.
    1. Ask Agent Blink to recommend a response action based on the case context. Review the suggested action and, when ready, select Run to execute the response workflow.