# AQUILA EDR - Execute Command and Response Actions

<span style="color: rgb(53, 152, 219);">**Prerequisites**</span>

- <span style="color: rgb(0, 0, 0);">**Access to CyTech - AQUILA**</span>
    - <span style="color: rgb(0, 0, 0);">Only users assigned the **"Owner"** or **"Admin"** role can access the Log Collector installation resources within the platform.</span>
- <span style="color: rgb(0, 0, 0);">Host must be online (offline actions queue and expire after ~2 weeks)</span>

<span style="color: rgb(53, 152, 219);">**What is the Response Console?**</span>

<span style="color: rgb(0, 0, 0);">The Response Console is a terminal-like interface in Elastic Security that lets you run live response actions directly on an endpoint. It provides near-real-time feedback and supports all major platforms: Linux, macOS, and Windows.</span>

<span style="color: rgb(53, 152, 219);">**Key Characteristics**</span>

- <span style="color: rgb(0, 0, 0);">Terminal-style input: Type commands and see results immediately</span>
- <span style="color: rgb(0, 0, 0);">Cross-platform: Works on Linux, macOS, and Windows endpoints</span>
- <span style="color: rgb(0, 0, 0);">Live interaction: Actions execute on the target host with quick output</span>

<span style="color: rgb(53, 152, 219);">**How to Open Response Console** </span>

**<span style="color: rgb(0, 0, 0);">Cyber Monitoring→ Endpoind Detection and Response (EDR) → Endpoints   
  
</span>**

<span style="color: rgb(0, 0, 0);">**→ Take action → Respond**</span>

<span style="color: rgb(0, 0, 0);"><span style="color: rgb(53, 152, 219);">**Core Commands** </span>(enter in console + Enter)</span>

<div id="bkmrk-command-purpose-synt"><div dir="auto"><table dir="auto" style="width: 100%;"><thead><tr><th data-col-size="xs" style="width: 18.3607%;"><span style="color: rgb(0, 0, 0);">Command</span></th><th data-col-size="lg" style="width: 20.5067%;"><span style="color: rgb(0, 0, 0);">Purpose</span></th><th data-col-size="lg" style="width: 32.9061%;"><span style="color: rgb(0, 0, 0);">Syntax Example</span></th><th data-col-size="lg" style="width: 28.2563%;"><span style="color: rgb(0, 0, 0);">Key Notes / Limitations</span></th></tr></thead><tbody><tr><td data-col-size="xs" style="width: 18.3607%;"><span style="color: rgb(0, 0, 0);">**isolate**</span></td><td data-col-size="lg" style="width: 20.5067%;"><span style="color: rgb(0, 0, 0);">Block all network communication</span></td><td data-col-size="lg" style="width: 32.9061%;"><span style="color: rgb(0, 0, 0);">isolate --comment "Suspicious activity"</span></td><td data-col-size="lg" style="width: 28.2563%;"><span style="color: rgb(0, 0, 0);">Immediate; irreversible without release</span></td></tr><tr><td data-col-size="xs" style="width: 18.3607%;"><span style="color: rgb(0, 0, 0);">**release**</span></td><td data-col-size="lg" style="width: 20.5067%;"><span style="color: rgb(0, 0, 0);">Restore network access</span></td><td data-col-size="lg" style="width: 32.9061%;"><span style="color: rgb(0, 0, 0);">release --comment "False positive"</span></td><td data-col-size="lg" style="width: 28.2563%;"><span style="color: rgb(0, 0, 0);">Reverses isolation</span></td></tr><tr><td data-col-size="xs" style="width: 18.3607%;"><span style="color: rgb(0, 0, 0);">**status**</span></td><td data-col-size="lg" style="width: 20.5067%;"><span style="color: rgb(0, 0, 0);">Show host status (agent, policy, last seen)</span></td><td data-col-size="lg" style="width: 32.9061%;"><span style="color: rgb(0, 0, 0);">status</span></td><td data-col-size="lg" style="width: 28.2563%;"><span style="color: rgb(0, 0, 0);">Quick health check</span></td></tr><tr><td data-col-size="xs" style="width: 18.3607%;"><span style="color: rgb(0, 0, 0);">**processes**</span></td><td data-col-size="lg" style="width: 20.5067%;"><span style="color: rgb(0, 0, 0);">List running processes</span></td><td data-col-size="lg" style="width: 32.9061%;"><span style="color: rgb(0, 0, 0);">processes</span></td><td data-col-size="lg" style="width: 28.2563%;"><span style="color: rgb(0, 0, 0);">Takes ~1 min; get PID or entityId</span></td></tr><tr><td data-col-size="xs" style="width: 18.3607%;"><span style="color: rgb(0, 0, 0);">**kill-process**</span></td><td data-col-size="lg" style="width: 20.5067%;"><span style="color: rgb(0, 0, 0);">Terminate a process</span></td><td data-col-size="lg" style="width: 32.9061%;"><span style="color: rgb(0, 0, 0);">kill-process --pid 123 or --entityId id</span></td><td data-col-size="lg" style="width: 28.2563%;"><span style="color: rgb(0, 0, 0);">Use entityId for reliability; SentinelOne: --processName</span></td></tr><tr><td data-col-size="xs" style="width: 18.3607%;"><span style="color: rgb(0, 0, 0);">**suspend-process**</span></td><td data-col-size="lg" style="width: 20.5067%;"><span style="color: rgb(0, 0, 0);">Pause a process</span></td><td data-col-size="lg" style="width: 32.9061%;"><span style="color: rgb(0, 0, 0);">suspend-process --pid 123 or --entityId id</span></td><td data-col-size="lg" style="width: 28.2563%;"><span style="color: rgb(0, 0, 0);">Reversible by killing or resuming</span></td></tr><tr><td data-col-size="xs" style="width: 18.3607%;"><span style="color: rgb(0, 0, 0);">**get-file**</span></td><td data-col-size="lg" style="width: 20.5067%;"><span style="color: rgb(0, 0, 0);">Download file (as password-protected ZIP)</span></td><td data-col-size="lg" style="width: 32.9061%;"><span style="color: rgb(0, 0, 0);">get-file --path "/path/to/file"</span></td><td data-col-size="lg" style="width: 28.2563%;"><span style="color: rgb(0, 0, 0);">Max 100 MB; password = elastic (may differ for third-party); use quarantine path from alerts</span></td></tr><tr><td data-col-size="xs" style="width: 18.3607%;"><span style="color: rgb(0, 0, 0);">**execute**</span></td><td data-col-size="lg" style="width: 20.5067%;"><span style="color: rgb(0, 0, 0);">Run shell command</span></td><td data-col-size="lg" style="width: 32.9061%;"><span style="color: rgb(0, 0, 0);">execute --command "whoami" --timeout 10s</span></td><td data-col-size="lg" style="width: 28.2563%;"><span style="color: rgb(0, 0, 0);">Output limited (~2000 chars); full in ZIP (password elastic); dangerous—use carefully</span></td></tr><tr><td data-col-size="xs" style="width: 18.3607%;"><span style="color: rgb(0, 0, 0);">**upload**</span></td><td data-col-size="lg" style="width: 20.5067%;"><span style="color: rgb(0, 0, 0);">Upload file to host</span></td><td data-col-size="lg" style="width: 32.9061%;"><span style="color: rgb(0, 0, 0);">upload --file &lt;select file&gt; --overwrite</span></td><td data-col-size="lg" style="width: 28.2563%;"><span style="color: rgb(0, 0, 0);">Max 25 MB (configurable up to 100 MB); default path = Endpoint install dir</span></td></tr><tr><td data-col-size="xs" style="width: 18.3607%;"><span style="color: rgb(0, 0, 0);">**scan**</span></td><td data-col-size="lg" style="width: 20.5067%;"><span style="color: rgb(0, 0, 0);">Malware scan on file/directory</span></td><td data-col-size="lg" style="width: 32.9061%;"><span style="color: rgb(0, 0, 0);">scan --path "/path"</span></td><td data-col-size="lg" style="width: 28.2563%;"><span style="color: rgb(0, 0, 0);">Uses current Defend policy (Detect/Prevent)</span></td></tr><tr><td data-col-size="xs" style="width: 18.3607%;"><span style="color: rgb(0, 0, 0);">**runscript**</span></td><td data-col-size="lg" style="width: 20.5067%;"><span style="color: rgb(0, 0, 0);">Run script (vendor-specific)</span></td><td data-col-size="lg" style="width: 32.9061%;"><span style="color: rgb(0, 0, 0);">CrowdStrike: runscript --CloudFile="script" Defender: runscript --ScriptName="script" SentinelOne: runscript --script="script"</span></td><td data-col-size="lg" style="width: 28.2563%;"><span style="color: rgb(0, 0, 0);">Syntax varies by EDR vendor; timeouts apply</span></td></tr><tr><td data-col-size="xs" style="width: 18.3607%;"><span style="color: rgb(0, 0, 0);">**cancel**</span></td><td data-col-size="lg" style="width: 20.5067%;"><span style="color: rgb(0, 0, 0);">Cancel pending action (Defender only)</span></td><td data-col-size="lg" style="width: 32.9061%;"><span style="color: rgb(0, 0, 0);">cancel --action "runscript"</span></td><td data-col-size="lg" style="width: 28.2563%;"><span style="color: rgb(0, 0, 0);">Microsoft Defender-specific</span></td></tr></tbody></table>

<div>  
To use the main commands, press the commands above, which are **Kill Process**, **Suspend Process,** **Running Processes**, **Get File**, **Upload File**, **Scan,** Example output below.  
  
</div></div></div>[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/a5OFwNFKUjlq1wuT-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/a5OFwNFKUjlq1wuT-image.png)

<div id="bkmrk--1"><div dir="auto"><div>  
</div></div></div><span style="color: rgb(53, 152, 219);">**Helpful Console Commands**</span>

- <span style="color: rgb(0, 0, 0);">help → List all available commands  
    </span>[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/relaYceDxo5CeKYm-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/relaYceDxo5CeKYm-image.png)
- <span style="color: rgb(0, 0, 0);">command --help → Detailed syntax for a command  
    </span>
- <span style="color: rgb(0, 0, 0);">--comment "text" → Add note to any action (logged in history)  
    </span>
- <span style="color: rgb(0, 0, 0);">clear → Clear console screen</span>

<span style="color: rgb(53, 152, 219);">**Response Actions History**</span>

- <span style="color: rgb(0, 0, 0);">Access: From console → **Response Actions History** link</span>
- <span style="color: rgb(0, 0, 0);">Shows: Who ran what, when, outcome, comments</span>
- <span style="color: rgb(0, 0, 0);">Use for auditing and troubleshooting</span>

<span style="color: rgb(53, 152, 219);">**Quick Tips**</span>

- <span style="color: rgb(0, 0, 0);">Always add --comment for traceability</span>
- <span style="color: rgb(0, 0, 0);">For quarantined files: Use get-file with path from alert (file.Ext.quarantine\_path)</span>
- <span style="color: rgb(0, 0, 0);">Third-party agents (CrowdStrike, Defender, SentinelOne) have vendor-specific syntax</span>
- <span style="color: rgb(0, 0, 0);">No way to cancel most actions once submitted—double-check before Enter</span>

 *If you need further assistance, kindly contact our technical support at **<support@cytechint.com>** for prompt assistance and guidance.*