After scan, how does file quarantine function work on an endpoint?
Quarantine is a feature of Cortex XDR that allows you to isolate a malicious file from its original location and prevent it from being executed. Quarantine works by moving the file to a protected folder on the endpoint and changing its permissions and attributes. Quarantine can be applied to files detected by periodic scans or by behavioral threat protection (BTP) rules. Quarantine is only supported for portable executable (PE) and dynamic link library (DLL) files. Quarantine does not affect the network connectivity or the communication of the endpoint with Cortex XDR.Reference:
Quarantine Malicious Files
Manage Quarantined Files
Juan
5 days agoTaryn
10 days agoGoldie
15 days agoMa
21 days agoLeontine
26 days agoLasandra
1 month agoLatosha
1 month agoAnnalee
1 month agoMaybelle
2 months agoKarma
2 months agoDorthy
2 months agoMagdalene
2 months agoElinore
2 months agoGracia
2 months ago