Skip to main content
Video: https://www.youtube.com/watch?v=SJjR-2ATRug

Goal

Run endpoint response actions (collection/containment) from CoPilot and verify outcomes.

When to use

  • During active incident response
  • For repeatable evidence collection workflows

Prereqs

  • Response/action capability is configured and tested

Procedure (high level)

  1. Select the action
  2. Target the correct endpoint
  3. Execute and monitor completion
  4. Review results and document in a case

Validation

  • Action completed successfully
  • Evidence/results captured and accessible