Skip to content

action: Agentless Local Containment (WinRM/SSH Fallback) #8

@keirsalterego

Description

@keirsalterego

Goal

Ensure containment actions can still execute even if the EDR API is temporarily down.

Scope

  • Implement fallback logic to isolate hosts using native OS commands (e.g., Windows Firewall rules via WinRM, iptables via SSH).
  • Trigger only if the primary EDR action fails or times out.

OpSec Mandate

Proxy must require explicit customer configuration of fallback credentials. Credentials must be stored in memory only.

Metadata

Metadata

Assignees

No one assigned

    Labels

    stage:saasStage 3: Full SaaS Operations (PRODUCTION)

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions