Restoring a quarantined file

Restoring a quarantined file allows an administrator to recover a file that was incorrectly identified as malicious.

Notes -

  • Restore a quarantined file if it was wrongly flagged (a false positive), and only after confirming that the file is safe.

  • To prevent the restored file from being quarantined again, you need to create a global exclusion.

To restore or exclude a quarantined file:

  1. Choose the file to restore using the multi-select checkboxes.
  2. Click Restore.

  3. Select one of these options:
    • To restore a file from quarantine, select Restore only.

      Notes:

      • The system restores the file to the same location from where it was quarantined.

      • If Endpoint Security detects the same file as malicious in any other endpoint, it quarantines the file again.

    • To restore a file and also exclude it from quarantine in the future, select Exclude and Restore.

      The system adds an exclusion to the Global Exclusions which affects all endpoints on the network, ensuring that the file is not flagged as malicious again.

  4. Click Proceed to complete the restoration.

    The system sends a push operation to the relevant device.