The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Restore quarantined objects on a client system

Prev Next

Restoring objects from the quarantine replaces all objects that the convicted processes created, changed, or deleted, and the files associated with those processes, on the system where they were before the Clean action occurred.

Before you begin

Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.

Task

Note

You must log on as Administrator to Restore or Delete items from the quarantine.

  1. Open the Trellix Endpoint Security (ENS) Client.

  2. Click Quarantine on the left side of the page.

    The page shows any items in the Quarantine.

    Note

    If the Trellix Endpoint Security (ENS) Client can't reach the Quarantine Manager, it displays a communication error message. In this case, restart the system to view the Quarantine page.

  3. Select an item from the top pane to display the details in the bottom pane.

  4. Select objects, click Restore, then click Restore again to confirm.

    Endpoint Security restores items to the original location and removes them from the quarantine. If an item is still a valid threat, Endpoint Security returns it to the quarantine the next time the item is accessed.

  5. On the Quarantine page, you can also perform these actions on objects in the quarantine.

    Note

    The Rescan button doesn't apply to objects quarantined by ATP.

    To...

    Follow these steps

    Delete items from the quarantine.

    Select items, click Delete, then click Delete again to confirm.

    Deleted items can't be restored.

    View an item in the Event Log.

    Select an item, then click the View in Event Log link in the details pane.

    The Event Log page opens, with the event related to the selected item highlighted.

    Get more information about a threat.

    Select an item, then click the Learn more about this threat link in the details pane.

    A new browser window opens to the Trellix Advanced Research Center website with more information about the threat that caused the item to be quarantined.

  6. After restoring a Windows service, reboot the client system to complete the restore.