Containment overview

Prev Next

The Endpoint Security (HX) Forensics workspace containment feature allows you to isolate host endpoints quickly and gives your enterprise a powerful weapon for preventing further compromise of host endpoint systems. Containing hosts suspends their access to and from network traffic, except for communication with IP addresses that your enterprise chooses to use in investigation and remediation and for network protocols necessary to maintain basic network connectivity. For example, Endpoint Security (HX) xAgent must always be able to communicate with appliances.

The Forensics workspace containment feature allows you to isolate host endpoints quickly and gives your enterprise a powerful weapon for preventing further compromise of host endpoint systems. Containing hosts suspends their access to and from network traffic, except for communication with IP addresses that your enterprise chooses to use in investigation and remediation and for network protocols necessary to maintain basic network connectivity. For example, Endpoint Security (HX) xAgent must always be able to communicate with appliances.

Your enterprise's administrators can allow additional communication for contained endpoints and customize other containment settings. You can make some hosts ineligible for containment, choose how to inform host endpoint users about a compromise, or even disable the containment feature completely.

Containment quickly stops attackers from controlling and using endpoints, but can also alert an attacker, causing them to employ new approaches. Additionally, containing an endpoint can interrupt potentially mission-critical work.

Note

Trellix Endpoint Security (HX) supports host containment for Windows, macOS, and Linux endpoints.

The Forensics workspace supports host containment for Windows, macOS, and Linux endpoints.

A contained host will remain contained as long as the Endpoint Security (HX) xAgent is installed and running on the host endpoint or you remove the host from containment. If the agent is shut down or uninstalled from a contained host, the host is no longer contained.