When an investigation is in progress or completed, you can respond to threats remotely using actions such as contain, remediate, or dismiss threats.
When responding to threats, containment and remediation strategy vary based on the type of threats. You can create separate strategies for each threat to contain and remediate.
The following criteria can be considered to determine the appropriate strategy:
Potential damage to the endpoint and data loss
Indicators of compromise evidence and preservation:
Trellix EDR provides IOCs and their associated risk.
Trellix EDR stores investigation created data until it is deleted by an administrator.
Service availability:
Trellix EDR provides the quarantine device feature capability, the quarantined devices are disconnected from the network and retains connectivity with Trellix products for further investigate and remediate a threat.
Make sure services connect to the quarantined devices are non-critical and taken into consideration as all services will get disrupted. However, you can exclude a service from quarantine using the Protection policy. Network Flow policy. For details, see Network Flow policy configuration.
For example, In the Network Flow policy, you can exclude the VPN client service from quarantine using its application path including .exe.
Application path including its .exe —
C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vacon64.exe;C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
Note
The Quarantine Device feature is supported on Windows and macOS endpoints.
Time and resources needed to implement the strategy:
Trellix EDR guided investigation automatically gathers, summarizes, and visualizes evidence from multiple sources and iterates as the investigation evolves. With an in-depth understanding of the threat and single-click response capabilities,Trellix EDR enables you to quickly and confidently respond to threats.
Trellix EDR reduces the expertise and effort needed to perform investigations and increases the speed with which analysts can determine the risk of incidents and their root cause.
Effectiveness of the strategy — based on the threat severity level, you can use Trellix EDR containment and remediation capability to respond to threats.
Duration of the solution:
For emergency and temporary workaround, you can useTrellix EDR containment methods.
For a permanent solution, you can use Trellix EDR remediation methods.
You can use the following methods to respond to threats remotely: