You can trigger response actions on a device using a registered event that is associated with such device. To trigger a response action, the event must be associated with a device that has the Endpoint Agent software component and is prepared to receive data from EPP applications.
When working with events, you can trigger the following response actions:
For events that are EDR incidents, you can trigger the Prevent run and Move to quarantine actions both for the threat detection object and for objects specified in other activity events with the File creation or Starting a process type.
To isolate a device associated with an event from the network:
You can select either an EDR incident or any event associated with the device running the Endpoint Agent software component.
The details area appears in the right part of the web interface window.
A window with a confirmation prompt opens.
The application will register a new response action. You can view information about this action in the Events section on the Response actions tab.
To prevent execution or move to quarantine a threat detection object:
You can select an EDR incident if the threat development chain includes an activity event with a threat detection object and the File creation or Starting a process type.
The details area appears in the right part of the web interface window.
A window with a confirmation prompt opens.
The application will register a new response action. You can view information about this action in the Events section on the Response actions tab.
To prevent execution or move to quarantine an object specified in any activity event with the File creation or Starting a process type in the threat development chain:
You can select an EDR incident.
The details area appears in the right part of the web interface window.
You can select any activity event with the File creation or Starting a process type. A key activity event (with a threat detection object) is marked with the Detection icon.
A window with a confirmation prompt opens.
The application will register a new response action. You can view information about this action in the Events section on the Response actions tab.
Page top