During an investigation, when you detect a malicious activity that might pose a threat to an endpoint, you can quickly stop the threat from damaging the endpoint and spreading to other endpoints. This action disconnects the endpoint from the network while retaining connectivity to Trellix products to further investigate and remediate the threat.
Log on to Trellix EDR as administrator.
Select Menu → Monitoring.
In the Threats by Ranking / Threats by Time pane, select a threat to view the affected endpoints.
In the Device pane, select one or more affected endpoints to enable the Device Actions drop-down list.
From the Device Actions menu, select Quarantine.
Click Confirm to complete the containment process.
You can check the action status to confirm that the Quarantine action is completed:
In the Monitoring dashboard, refresh the endpoint list.
Note
When the endpoint is in quarantine, a biohazard sign appears next to the device.
In the Action History dashboard, the Action Status displays the quarantine action as Completed.