Managing Quarantined Files
Quarantine Management helps protect the network by isolating potentially harmful files and applications (malware, ransomware, suspicious files, and so on), preventing threats from spreading across the environment. It offers a centralized view, enabling security teams to manage quarantined items efficiently. Administrators can respond quickly to incidents, inspect suspicious content, and resolve issues by restoring safe files or removing malicious ones.
To view the Quarantine Management page, from the left navigation panel, click Asset Management > Quarantine Management.
Quarantine Management feature is supported only on the Endpoint Security client for Windows version E89.05 and later.
Benefits
-
Centralized control: View and manage quarantined items across all endpoints from a unified location.
-
Safe investigation: Download and analyze quarantined files in a secure, password-protected format for further examination by SOC analysts.
-
Efficient threat response: Restore or delete files in bulk across impacted devices, swiftly addressing actual threats and false positives.
Viewing Quarantined Files and Applications
The Quarantine Management page shows all quarantined files and applications in two switchable views:
-
View by Files: Each row represents an individual file. Shows file details including name, path, hash, responsible blade, status, and the number of devices where this file was quarantined.
-
View by Devices: Each row represents an individual endpoint. It shows device details, including name, operating system, version, and the total count of quarantined files on that device.
To change the view, click Files or Devices next to View quarantined files.