Containment and remediation

Prev Next

The Forensics workspace containment feature allows you to isolate host endpoints quickly and gives your enterprise a powerful weapon for preventing further compromise of host endpoint systems. Containing hosts suspends their access to and from network traffic, except for communication with IP addresses that your enterprise chooses to use in investigation and remediation and for network protocols necessary to maintain basic network connectivity.

Your enterprise's administrators can allow additional communication for contained endpoints and customize other containment settings. You can make some hosts ineligible for containment, choose how to inform host endpoint users about a compromise, or even disable the containment feature completely.

Containment quickly stops attackers from controlling and using endpoints, but can also alert an attacker, causing them to employ new approaches. Additionally, containing an endpoint can interrupt potentially mission-critical work.

Note

The Forensics workspace supports host containment for Windows, macOS, and Linux endpoints.