thx for your question. Yes you can! This is one of our boot camp samples for shunning using custom action script for sam rules inside checkpoint.
The only problem is, that you need to login to your firewall 1st, which can only be done outside QRadar script container.
The workaround for this problem is to store ip addresses inside a reference list and read the updated list using a 2nd script with REST API and beeing scheduled once per minute from outside the script container in order to workaround jail.
Pls refer to PDF attached
------------------------------
[Karl] [Jaeger] [Business Partner]
[QRadar Specialist]
[pro4bizz]
[Karlsruhe] [Germany]
[4972190981722]
------------------------------