Skip to main content

Actions

An Action is a saved, versioned response, such as Isolate endpoint or Initiate patch. People run it without seeing or choosing the script underneath. Each Action sets:

  • what runs: a script (a pinned version, or the latest published one) or a built-in Scout verb such as kill;
  • the form people fill in when they run it, with presets;
  • which endpoints it can target (platforms, required tags);
  • its risk level and approval policy;
  • its default rollout and how long a run waits for offline endpoints;
  • optionally, the Action that undoes it.
Beta

This feature is currently rolling out and may not be enabled for your organization.

Starter Actions​

Every organization starts with these. They wrap the Huntbase pack.

ActionRunsRiskApprovalNotes
Isolate endpointisolate-hostHighTwo peopleUndone by Release endpoint. See Isolate an endpoint.
Release endpointrelease-hostLowNone
Initiate patchpatch-packageHighOrganization adminParameters: package, minimum version, reboot. Starts with a canary.
Collect triage bundletriage-bundleMediumNone
Kill process by nameBuilt-in killMediumNoneScout's own processes and system processes are still protected.
Disable local accountdisable-local-userHighTwo people

Create an Action​

  1. Open Library › Actions and click New action, then choose Endpoint.
  2. Pick the script and how it's pinned: Latest published, or a specific version.
  3. Build the run form from the script's arguments. Give each a label and default. Mark an argument Fixed to always use its default; it isn't asked at run time. Add Presets for common combinations.
  4. Optionally limit targets to some platforms or to endpoints carrying a tag.
  5. Set the risk level and approval policy: Organization default, None, Two people or Organization admin.
  6. Choose the default rollout and the run expiry (1 to 24 hours).
  7. Optionally choose the Action that undoes this one.
  8. Click Create action.

You can also start from an ad-hoc script run. On an endpoint's Actions tab, click Save as Action on the run.

Editing an Action saves a new version. Every run records the version it used.

The Action page​

TabShows
EndpointsThe latest outcome of this Action on every endpoint it has run on. For a paired Action it shows the current state, for example how many endpoints are isolated right now. Export it as CSV.
RunsEvery run of this Action. Each opens in Activity › Actions.
DefinitionWhat runs, the form, constraints, risk, approval and rollout.
VersionsEach saved version and who saved it.
AccessWho can edit, run and approve it.

Who can do what​

ToYou need
Run an ActionRunner on the Action (or organization admin) and response access to every targeted endpoint, on the fleet or on a tag they carry.
Approve a runApprover on the Action, or organization admin. Two-person approval never accepts the requester.
Create or editEditor on the Action, plus Runner on the script it wraps.

Running an Action does not need access to the script inside it.

Next​