Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Security Operations Integration- Isolate Host capability

The Isolate Host capability restricts system connections to other devices. Isolate host is executed against a configuration item (CI).

The Isolate Host capability has a flow, Security Operations - Isolate Host Flow that accepts one or more CIs and optionally an implementation. You can specify an implementation to use to isolate the host or for the flow to attempt to isolate the host using all implementations.

Note: While not integrated with a capability, a flow, Security Operations Carbon Black Integration- Remove Host Isolation Flow is available for orchestration to restore communication with an isolated host.

Note: If no implementations are available, capability actions are not displayed in product menus.

Parent Topic:Integration capabilities

Related topics

Security Operations Integration- Block Request capability

Security Operations Integration- Email Search and Delete capability

Security Operations Integration- Enrich CI capability

Security Operations Integration- Enrich Observable capability

Security Operations Integration- Get Network Statistics capability

Security Operations Integration- Get Running Processes capability

Security Operations Integration- Publish to Watchlist capability

Security Operations Integration- Sightings Search capability

Security Operations Integration - Threat Lookup capability

Change the order of flow execution