This section describes how to use the unlock code to uncontain your macOS host.
To use an unlock code to remove a macOS host from containment:
Log in to the contained macOS host.
Open Command line prompt and use the cd command to change to the/Library/FireEye/xagt/xagt.app/Contents/MacOS/bin directory for Agent version 31 and earlier or /Library/FireEye/xagt/xagt.app/Contents/MacOS directory for Agent version 32 and later:/Library/Trellix/XCLIENT/xclient.app/Contents/MacOS/bin
cd /Library/FireEye/xagt/xagt.app/Contents/MacOS/bin cd /Library/Trellix/XCLIENT/xclient.app/Contents/MacOS/bin
Run the uncontain executable file with the unlock code:
Endpoint Detection and Response with Forensics (EDRF) > Respond to threats with EDRF > Containment and remediation > Containing host endpoints > Manage containment > Stopping containment using an unlock code