Managing File Quarantine

Prev Next

The malware protection feature allows you to quarantine infected files to prevent the spread of malware on your host endpoints.

When you enable malware detection (Signature and Heuristic Detection) and quarantine on all of your host endpoints or select host sets in your environment, infected files are automatically copied to a quarantine location. After relocating the infected file to quarantine, malware protection attempts to clean the file by removing malicious code. You can manage quarantined files from the Endpoint Security Web UI by acquiring the file from the quarantine area, restoring the file to its normal location on the endpoint, and deleting the file from quarantine.

Quarantined files are stored in the quarantine area on the host endpoint until you manually delete them, manually restore them, or they exceed the quarantine file aging period. See "Deleting Quarantined Files" in the Endpoint Security (HX) Server User Guide for more information on manually deleting quarantined files. You can configure the quarantine file aging period in the Endpoint Security (HX) Web UI. The default quarantine file aging period is 90 days. See Setting the Aging Interval for Quarantine Files for more information.

This section covers how to use the Web UI to enable and disable file quarantine for all of your host endpoints and for selected host sets in your environment. See the Endpoint Security (HX) REST API Guide for information on using the API to enable and disable file quarantine.

Enabling Quarantine

Important

Enabling quarantine may result in data loss when malware is blocked in an active process or file and malware protection terminates the process that started the infection.

To enable quarantine for all host endpoints:

Important

Signature and Heuristic Detection must be enabled before you can enable quarantine.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the Agent Default Policy link to access the Edit Policy page.

  4. Select the Malware Protection tab.

  5. Verify that the Signature and Heuristic Detection switch is ON.

    Policy_MalDetect_SH_Enable.png
  6. In the Quarantine section, toggle the Quarantine ON/OFF switch to ON.

    Policy_MalProtect_Quarantine_Enable.png
  7. Click Save.

To enable quarantine for selected host sets:

Note

See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Select the Malware Protection tab.

  5. Verify that the Signature and Heuristic Detection switch is ON.

    Policy_MalDetect_SH_Enable.png

    Important

    Signature and Heuristic Detection must be enabled before you can enable quarantine.

  6. In the Quarantine section, toggle the Quarantine ON/OFF switch to ON.

    Policy_MalProtect_Quarantine_Enable.png
  7. Click Save.

Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.

Disabling Quarantine

Note

When quarantine is disabled, all malware protection remediation and notification actions are automatically disabled.

To disable quarantine for all host endpoints.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the Agent Default Policy link to go to the Edit Policy page.

  4. Select the Malware Protection tab.

  5. In the Quarantine section, toggle the Quarantine ON/OFF switch to OFF.

    Policy_MalProtect_Quarantine_Disable.png
  6. Click Save.

To disable quarantine for selected host sets.

Note

When you disable a setting in a custom policy, the setting is disabled for all host sets assigned to the policy. If you want select host sets to keep the original setting, you must create a new custom policy with the setting enabled and assign it to the selected host sets. See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Select the Malware Protection tab.

  5. In the Quarantine section, toggle the Quarantine ON/OFF switch to OFF.

    Policy_MalProtect_Quarantine_Disable.png
  6. Click Save.