Before the Endpoint Security (HX) contains a host, a containment request must be made and then approved by an administrator or investigator. Then the Endpoint Security (HX) prepares a containment job for the EDRF Client, containing instructions about how to contain the host. The EDRF Client carries out these instructions and reports back to the Endpoint Security (HX).
During the containment process, host endpoints pass through a series of containment states (or status changes). Wherever the Endpoint Security (HX) lists hosts, containment status icons are displayed for each host:
Status icon | Description |
|---|---|
![]() | Containment requested |
![]() | Containment approved |
![]() | Contained |
![]() | Containment failed |
![]() | Stopping containment |
![]() | Containment cancellation failed |
Generally, all Endpoint Security (HX) tasks are processed on a first come, first serve basis. Containment tasks, however, are explicitly marked as high-priority tasks and will pre-empt any data acquisition tasks, such as Enterprise Search and data acquisition requests.




