hec_quarantine_events
Quarantine security events by ID to stop threats and protect access. Returns task IDs for tracking; reversible via restore. Confirm before invoking.
Instructions
⚠ HIGH-IMPACT. Quarantine one or more security events by event ID. Quarantining is reversible via restore but affects user access to events. Returns task IDs to track progress. Confirm with the user before invoking.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| eventIds | Yes | List of event IDs to quarantine |