I don't believe there is a way to do an automated response for AMP events in ISE. The only attributes that are supported are:
-
Threat:Qualys-CVSS_Base_Score
-
Threat:Qualys-CVSS_Temporal_Score
-
Rapid7 Nexpose-CVSS_Base_Score
-
Tenable Security Center-CVSS_Base_Score
-
Tenable Security Center-CVSS_Temporal_Score
I know at Live they demonstrated this working but I believe it was with FMC in the mix. FMC/FTD would learn about the vulnerable endpoint and issue a quarantine to ISE. I think Aaron presented on that two years ago, but I may not be remembering that correctly.