The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Restore the quarantined items

Prev Next

Restore the quarantined items from the managed Linux endpoints for sending it for further analysis.

  1. Log on to the ePO - On-prem server as an administrator.

  2. Select MenuClient Task Catalog.

  3. In Client Task Types, expand Endpoint Security Threat Prevention, select Restore from Quarantine, click New Task, then select Restore from Quarantine from the Task Types.

  4. In the Client Task Catalog page, define these settings:

    • Task name — Specifies the name of the task.

    • Description — Specifies the purpose of the task and its other references.

    • Items to Restore — Specifies the exact detection name of the item to restore.

  5. Review the settings, then click Save.

    For information about restoring the quarantined items on a standalone system, see Trellix Knowledge Base article KB88067.