You can delete quarantined items, restore or rescan them, or get more information about the threat.
Note
Starting with Endpoint Security 10.7.20, the Restore and Delete buttons are hidden when the client interface is in Standard access mode. To use these features, you must Log on as administrator. In earlier versions, these options were available to all users.
To improve security, Endpoint Security restricts the ability to restore or delete items from the Quarantine console based on the interface access mode. This prevents unauthorized users from restoring potentially malicious files that were isolated by On-Access Scanning (OAS) or Adaptive Threat Protection.
Quarantined items can include various types of scanned objects, such as files, registries, or anything that Endpoint Security scans for malware. Threat Prevention cleans or deletes items that are detected as threats and saves copies in a non-executable format to the Quarantine folder.
For information about malware detection names, see the Trellix Advanced Research Center page.
Open the Trellix Endpoint Security (ENS) Client.
From the Action menu
, select Administrator Log On.In the Password field, enter the administrator password, then click Log On.
Click Quarantine on the left side of the page.
The page shows any items in the Quarantine.
Note
If the Trellix Endpoint Security (ENS) Client can't reach the Quarantine Manager, it displays a communication error message. In this case, restart the system to view the Quarantine page.
Select an item from the top pane to display the details in the bottom pane.
On the Quarantine page, perform actions on selected items.
To...
Follow these steps
Delete items from the quarantine.
Select items, click Delete, then click Delete again to confirm.
Deleted items can't be restored.
Restore items from the quarantine.
Select items, click Restore, then click Restore again to confirm.
Endpoint Security restores items to the original location and removes them from the quarantine.
If an item is still a valid threat, Endpoint Security returns it to the quarantine the next time the item is accessed.
Rescan items.
Select items, then click Rescan.
For example, you might rescan an item after updating your protection. If the item is no longer a threat, you can restore the item to its original location and remove it from the quarantine.
View an item in the Event Log.
Select an item, then click the View in Event Log link in the details pane.
The Event Log page opens, with the event related to the selected item highlighted.
Get more information about a threat.
Select an item, then click the Learn more about this threat link in the details pane.
A new browser window opens to the Trellix Advanced Research Center website with more information about the threat that caused the item to be quarantined.