Skip to main content

Taking Action on Threats

Execute response actions to contain and remediate security threats.

Rollback Capabilities

All actions include rollback capabilities and maintain a complete audit trail for compliance.


Response Actions Overview

CastellanAI provides automated and manual response actions to quickly contain threats and minimize damage.

CapabilityDescription
AI-Suggested ActionsAI analyzes threats and suggests appropriate responses
Manual ExecutionSecurity teams can manually trigger actions
Rollback SupportUndo actions within the rollback window
Audit TrailComplete logging of all actions taken

Available Response Actions

Block IP Address

Immediately block malicious IP addresses at the firewall level.

Common Uses:

  • Brute force attacks from external IPs
  • Command & control server communications
  • Data exfiltration attempts
  • Port scanning and reconnaissance

Rollback Window: 24 hours

Scope

IP blocks apply at the network perimeter. Internal traffic may require additional controls.


How to Execute Actions

From Event Details

  1. Navigate to DashboardEvents
  2. Click on any security event to view details
  3. Review AI-suggested actions in "Recommended Actions"
  4. Click Execute on the desired action
  5. Confirm execution in the dialog

Action Lifecycle

StageDescription
1. SuggestedAI analyzes the threat and suggests appropriate actions
2. PendingAction queued for execution, awaiting confirmation
3. ExecutedAction successfully executed, state captured for rollback
4. Rolled BackAction undone within the rollback window

Rollback Windows

Action TypeRollback WindowNotes
Block IP24 hoursNetwork rules removed
Isolate Host48 hoursEndpoint reconnected
Quarantine File7 daysFile restored to original location
Add to Watchlist30 daysEnhanced monitoring removed
Create TicketN/ATicket remains for audit trail
🔄 How to Rollback an Action
  1. Navigate to DashboardActions
  2. Find the executed action in the list
  3. Click "Rollback" button (if within window)
  4. Confirm rollback in the dialog
  5. Action will be reversed and logged
Rollback Limitations

Some actions cannot be rolled back after certain events (e.g., if malware executed after quarantine was rolled back).


Best Practices

PracticeDescription
Review Event ContextAlways review full event details before executing
Start Less DisruptiveBegin with watchlist before escalating to isolation
Use Rollback WindowsActions can be undone if needed
Document DecisionsAdd notes explaining your rationale
Monitor ResultsVerify execution status in Actions dashboard
⚠️ Common Mistakes to Avoid
MistakeImpactSolution
Isolating without stakeholder noticeBusiness disruptionCoordinate before critical actions
Blocking IP without investigatingMay block legitimate trafficReview context first
Ignoring rollback windowsPermanent actionPlan for potential reversal
Skipping documentationCompliance gapsAlways add action notes

What's Next?

GuideDescription
Incident WorkflowsCreate automated incident response workflows
Investigating EventsSecurity event investigation techniques
Threat RemediationComplete threat removal procedures
Generating ReportsDocument your response actions