During an investigation, you can disconnect the endpoint from the network to contain a threat while retaining connectivity with other Trellix products to further investigate and remediate a threat using the Investigating dashboard.
Important
Make sure Enable Plug-in is selected on the Network Flow policy page for quarantine and end quarantine to work on the endpoint.
The Quarantine Device feature is supported on Windows and macOS endpoints.
Log on to Trellix EDR.
Select Menu → Investigating.
Open an existing investigation created and navigate to Investigated Items.
Click Investigated Items and select device(s).
A device detail appears on the right pane.
On the Finding details pane, click a hostname and select Quarantine Device action from the Take action menu.
On the Action History dashboard, Action Status displays the quarantine device action as Completed.