C

Quarantine Host

v1Verified
crowdstrike.quarantine_host
securitycriticalMFA Required

Network-isolates an endpoint via CrowdStrike Real Time Response. Host retains connection to Falcon cloud only. Requires MFA approval.

Technical Specs

External Calls

https://api.crowdstrike.com/devices/entities/devices-actions/v2

Data Classification

critical

MFA Timeout

300 seconds

Enforcement

Rust / fail-closed

Usage in Manifest

Add this snippet to your agent manifest file to enable this tool.

{
  "tools": [
    {
      "name": "crowdstrike.quarantine_host",
      "version": "1"
    }
  ],
  "mfa_required_for": [
    "crowdstrike.quarantine_host"
  ]
}

Used By

2

2 agents currently use this tool

All calls are logged to the tamper evident audit chain

Trust & Security

Ed25519 signed descriptor
Rust enforcement, fail-closed
Every call logged to tamper evident chain
Per-agent MFA configuration

Add to Agent

Use this tool in your agent. Sign in to add it to a new or existing agent.

Via CLI

agentsight tool add \
  --name crowdstrike.quarantine_host \
  --version 1
  --mfa-required