After scan, how does file quarantine function work on an endpoint?
Quarantine is a feature of Cortex XDR that allows you to isolate a malicious file from its original location and prevent it from being executed. Quarantine works by moving the file to a protected folder on the endpoint and changing its permissions and attributes. Quarantine can be applied to files detected by periodic scans or by behavioral threat protection (BTP) rules. Quarantine is only supported for portable executable (PE) and dynamic link library (DLL) files. Quarantine does not affect the network connectivity or the communication of the endpoint with Cortex XDR.Reference:
Quarantine Malicious Files
Manage Quarantined Files
Krystal
3 days agoAgustin
9 days agoRenay
14 days agoRosalyn
19 days agoThurman
24 days agoJackie
29 days agoJuan
2 months agoTaryn
2 months agoGoldie
2 months agoMa
2 months agoLeontine
2 months agoLasandra
3 months agoLatosha
3 months agoAnnalee
3 months agoMaybelle
3 months agoKarma
3 months agoDorthy
3 months agoMagdalene
4 months agoElinore
4 months agoGracia
4 months ago