Contain or remediate threats using the Monitoring dashboard

Prev Next

If a threat affects multiple devices, you can stop the threat from spreading to other connected devices and minimize the impact of an attack. You can apply an action from the Monitoring dashboard or from the Real-time Search page.

  1. Log on to Trellix EDR as administrator.

  2. Select MenuMonitoring.

  3. On the Threats by Ranking / Threats by Time pane, select a potential threat to view the affected devices.

    Tip

    Use the Search filter in the Threats by Ranking / Threats by Time to find threats by name or ID.

  4. On the Device pane, select one or more affected devices to enable the Device Actions drop-down list.

  5. To contain the threat on one or more affected devices, select an option from the Device Actions menu:

    • Stop process — Stops the process tree (parent and child processes).

    • Stop and remove — Stops the process tree (parent and child processes) and removes the file from the selected devices.

    • Quarantine — Isolates the device from the network while retaining connectivity to Trellix products, allowing only network communication from Trellix trusted processes and blocking all others. If the selected devices are offline, the quarantine is imposed when the devices are online. You can continue to run real-time or historical searches on this device with Trellix EDR to investigate the potential threat.

      A message notifies the user of the quarantine/end quarantine action and the quarantine is maintained between rebooting and shutting down. A biohazard icon to the left of the device name indicates that it is quarantined.

    • End Quarantine — Removes the quarantine and reconnects the device to the network. This option is disabled when the device is not in a quarantined state.

  6. Click Confirm to complete the containment process.

    The device or process affected is contained and the threat is stopped from spreading to other devices in the same network.