Using an unlock code to uncontain a macOS host

Prev Next

This section describes how to use the unlock code to uncontain your macOS host.

To use an unlock code to remove a macOS host from containment:
  1. Log in to the contained macOS host.

  2. Open Command line prompt and use the cd command to change to the /Library/FireEye/xagt/xagt.app/Contents/MacOS/bin directory for Agent version 31 and earlier or /Library/FireEye/xagt/xagt.app/Contents/MacOS directory for Agent version 32 and later: /Library/Trellix/XCLIENT/xclient.app/Contents/MacOS/bin

    cd /Library/FireEye/xagt/xagt.app/Contents/MacOS/bin cd /Library/Trellix/XCLIENT/xclient.app/Contents/MacOS/bin

  3. Run the uncontain executable file with the unlock code:

    ./uncontain <unlock code>