Run Block Request
Blocks communication with observables associated with a security incident.
Before you begin
Role required: sn_si.analyst
About this task
Note: If no implementations are available, capability actions are not displayed in product menus.
The Security Operations Integration - Block Request flow can be triggered from an observable form, or from the Security Incident Observables related list on a security incident.
This example shows a Block Request from a security incident.
Procedure
Navigate to a security incident.
In the Related Links, select Show all Related Lists.
Select Associated Observables tab.
Select observables from the list.
Select Allow/Block Request in the Actions on selected rows... drop-down menu.
A dialog box appears.
Select look-up icon next to the Implementation field.
Select a capability from the list.
Following fields appear if the capability includes additional runtime parameters. Different integrations may have different parameters.
| Field | Description |
|---|---|
| Indicator Block Action Type | Option to control how the detection is handled after the block request is submitted.Options include: - Block - Block, hide detection |
| Severity | Option to specify the severity assigned to the indicator in CrowdStrike when the block action is submitted.Options include: - Informal - Low - Medium - High - Critical |
Select Submit.
The flow execution audit is displayed in the work notes section.
Block Request work note example
Parent Topic:Security Operations Integration- Block Request capability