External DocumentationTo learn more, visit the Cortex XDR documentation.
Actions
Add Files To Block List
Adds files which do not exist in the allow or block lists to a block list.

Preview this Workflow on desktop
Was this page helpful?
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
| Parameter | Description |
|---|---|
| Comment | Additional information regarding the action. |
| File Hashes List | A comma-separated list of file hashes which will be added to a block list. |
| Incident ID | String representing the incident ID. When included in the request, the Isolate Endpoints action will appear in the Cortex XDR Incident View Timeline tab. |
true
Was this page helpful?