Respond to threats

Prev Next

When an investigation is in progress or completed, you can respond to threats remotely using actions such as contain, remediate, or dismiss threats.

When responding to threats, containment and remediation strategy vary based on the type of threats. You can create separate strategies for each threat to contain and remediate.

The following criteria can be considered to determine the appropriate strategy:

  • Potential damage to the endpoint and data loss

  • Indicators of compromise evidence and preservation:

    • EDRF provides IOCs and their associated risk.

    • EDRF stores investigation created data until it is deleted by an administrator.

  • Service availability:

    • EDRF provides the quarantine device feature capability, the quarantined devices are disconnected from the network and retains connectivity with Trellix products for further investigate and remediate a threat.

    • Make sure services connect to the quarantined devices are non-critical and taken into consideration as all services will get disrupted. However, you can exclude a service from quarantine using the Protection policy. For details, see Configure Protection Policy.

      For example, In the Network Flow policy, you can exclude the VPN client service from quarantine using its application path including .exe.

      Application path including its .exe — C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vacon64.exe;C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe

  • Time and resources needed to implement the strategy:

    • EDRF guided investigation automatically gathers, summarizes, and visualizes evidence from multiple sources and iterates as the investigation evolves. With an in-depth understanding of the threat and single-click response capabilities,EDRF enables you to quickly and confidently respond to threats.

    • EDRF reduces the expertise and effort needed to perform investigations and increases the speed with which analysts can determine the risk of incidents and their root cause.

  • Effectiveness of the strategy — based on the threat severity level, you can use EDRF containment and remediation capability to respond to threats.

  • Duration of the solution:

    • For emergency and temporary workaround, you can useEDRF containment methods.

    • For a permanent solution, you can use EDRF remediation methods.

You can use the following methods to respond to threats remotely: