Contain threats

Prev Next

During an investigation, when you detect a malicious activity that might pose a threat to an endpoint, you can take action to contain threats remotely. This action provides protection to the endpoint and avoids spreading to other endpoints.

During containment, EDRF identifies all affected endpoints within the environment so that threats from the affected endpoints are contained.

If the target endpoints are offline when the containment reaction is executed, the response reaction is saved and executed when the endpoint is back online.

Important

Run the HostInfo query on Real-time Search to list endpoints and their connectivity status (online or offline).

When you execute a reaction and select all displayed results to take action, the action is executed on all impacted endpoints present in your environment. This includes endpoints not responded to the search query due to endpoint shutdown, connectivity issue, etc.

Below are points on why containment is important early in the course of handling threats:

  • To reduce the increase in threats damage on the endpoint.

  • To avoid spreading threats in the environment.

  • To minimize the impact to zero without any data loss.

  • To provide time for developing a tailored remediation strategy.

You can use the following reactions to respond to threats remotely:

You can also create and execute custom reactions to respond to threats.