Quarantine devices using the Real-time Search dashboard

Prev Next

During an investigation, you can disconnect the endpoint from the network to contain a threat while retaining connectivity with other Trellix products to further investigate and remediate a threat using the Real-time Search dashboard.

Important

Make sure Enable Plug-in is selected on the Network Flow policy page for quarantine and end quarantine to work on the endpoint.

The Quarantine Device feature is supported on Windows and macOS endpoints.

  1. Log on to Trellix EDR.

  2. Select MenuReal-time Search.

  3. On the Search box, enter a search expression.

  4. Click the search icon to start collecting data from managed devices.

  5. Based on the search expression, the list of events, processes, or devices is displayed.

  6. From the list, select the affected event, process, or device, then select ActionContainQuarantine Device.

    A new window appears to complete the action.

  7. Click Confirm to complete the Quarantine Device action.

    A confirmation message displays as the action launched is completed successfully.

  8. On the Action History dashboard, Action Status displays the quarantine device action as Completed.