Using an unlock code to uncontain a Windows host Published on Sep 10, 2026
Print
Copy page Copy as Markdown for LLMs View as Markdown View the page as plain text
Open in ChatGPT Ask ChatGPT about this page Open in Claude Ask Claude about this page Prev Next This section describes how to use the unlock code to uncontain your Windows host.
To use an unlock code to remove a Windows host from containment:
Log in to the contained Windows host.
Open Command line prompt and use the cd command to change to the C:\Windows\FireEye C:\Windows\Trellix\XClient\uncontain.exe directory:
cd C:\Windows\FireEyecd C:\Windows\Trellix\XClient\uncontain.exe
Run the uncontain executable file with the unlock code:
uncontain.exe <unlock code>
Was this article helpful?
Yes No
Related articles
Endpoint Detection and Response with Forensics (EDRF) > Respond to threats with EDRF > Containment and remediation > Containing host endpoints > Manage containment > Stopping containment using an unlock code
Endpoint Security (HX) > Endpoint Security (HX) Server 10.x User Guide > Containing host endpoints > Manage containment > Stopping containment using an unlock code
Endpoint Security (HX) > Endpoint Security (HX) Server 10.x User Guide > Containing host endpoints > Manage containment > Stopping containment using an unlock code