Kaspersky Endpoint Security 12 for Mac

Move file to Quarantine

July 2, 2024

ID 276111

Expand all | Collapse all

When reacting to threats, Kaspersky Endpoint Detection and Response can create Move file to Quarantine tasks. This is necessary to minimize the consequences of the threat. Quarantine is a special local storage on the computer. The user can quarantine files that the user considers dangerous for the computer. Quarantined files are stored in an encrypted state and do not threaten the security of the device. Kaspersky Endpoint Security uses Backup as a file storage. For details on managing Quarantine as part of solutions, please refer to the Kaspersky Endpoint Detection and Response Optimum Help.

You can create Move file to Quarantine tasks in the following ways:

  • In alert details (only for EDR Optimum).

    Alert Details is a tool for viewing the entirety of collected information about a detected threat. Alert details include, for example, the history of files appearing on the computer. For details about managing alert details, refer to the Kaspersky Endpoint Detection and Response Optimum Help.

  • Using the Task Wizard.

    You must enter the file path or hash (SHA256 or MD5), or both the file path and the file hash.

The Move file to Quarantine task has the following limitations:

  • The file size must not exceed 100 MB.
  • System Critical Objects (SCO) cannot be quarantined. SCOs are files that the operating system and the Kaspersky Endpoint Security for Windows application require to be able to run.
  • You can configure the task for EDR Optimum in Web Console and Cloud Console.
  • The Backup capacity is limited by the free disk space.

To create a Move file to Quarantine task:

  1. In the main window of the Web Console, select Devices > Tasks.

    The list of tasks opens.

  2. Click Add.

    The New task wizard starts.

  3. Configure the task settings:
    1. In the Application drop-down list, select Kaspersky Endpoint Security for Mac (12.1).
    2. In the Task type drop-down list, select Move file to Quarantine.
    3. In the Task name field, enter a brief description.
    4. Select one of the following options:
      • Assign task to an administration group
      • Specify device addresses manually or import addresses from a list
      • Assign task to a device selection
  4. Select devices according to the selected task scope option.
  5. At the Task scope step, specify an administration group, devices with specific addresses, or a device selection.

    The available settings depend on the option selected at the previous step.

  6. In the list of files, click Add.

    The file adding wizard starts.

  7. In the Specify the file to move to Quarantine drop-down list, select one of the options and fill in the required fields. To add the file, you must enter the full path to the file, or both file hash and the path.
  8. Enter the account credentials of the user whose rights you want to use to run the task. Click Next.

    Note: By default, Kaspersky Endpoint Security starts the task as the system user account (root).

  9. At the Finish task creation step, click the Finish button to create the task and close the wizard.

    If you enabled the Open task details when creation is complete option, the task settings window opens. In this window, you can check the task parameters, modify them, or configure a task start schedule, if necessary.

  10. Click the new task.

    The task properties window opens.

  11. Select the Schedule tab.
  12. Configure the task schedule.

    Note: Make sure the computer is turned on to run the task.

  13. Click the Save button.
  14. To run the task immediately regardless of the configured schedule, do the following:
    1. Select the checkbox next to the task.
  15. Click the Run button.

As a result, Kaspersky Endpoint Security moves the file to Quarantine.

The Move file to Quarantine task can finish with the Access denied error if you are trying to quarantine an executable file that is currently running. Create a terminate process task for the file and try again.

The Move file to Quarantine task can finish with the Not enough space in Quarantine storage error if you are trying to quarantine a file that is too large. Free up the disk space and try again.

.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.