Security Operations

Containment Actions

Limit the damage before the analysis is finished

With ransomware, what counts is the time between the first alert and disconnecting the affected machine. Until now that step happened outside the platform: someone reads the alert, switches to the endpoint protection console or the directory and acts there. This module brings the intervention to where the incident is documented anyway, and gives it the same controls as any other intervention in the fleet: a second person, a justification, a log. An action is created as a request with a mandatory justification, waits for approval, is executed and, on first success, records the containment timestamp on the incident.

ISO 27001NIS2BSI IT-Grundschutz
Features

Your benefits

1

Four eyes, even under time pressure

Requesting and approving are separate rights held by separate people. When a rule chain requests the action, one approver suffices: the rule and the human are the two pairs of eyes.

2

Reversible, with a paper trail

Every action can be reverted, and the reversal needs its own approval. Only the device acknowledgement turns it into “reverted”, not the click.

3

Abort rather than guess

If the lookup finds no device or more than one, the action aborts and states the number. Disconnecting the wrong machine would be worse than disconnecting none.

4

Two routes to the same host

Via your own agent for machines that have one, via the EDR console for everything else. Both are separate actions with their own reversal and do not cancel each other out.

Capabilities

All capabilities at a glance

  • Host isolation via the agent: quarantine through the local firewall, or disable the network adapter
  • Session termination with an optional notice to the person affected, protected system accounts excluded
  • Account lockout via LDAP / Active Directory using a dedicated write service account
  • Account lockout via Entra ID, optionally revoking active sign-in sessions
  • EDR isolation for Microsoft Defender for Endpoint, CrowdStrike Falcon and SentinelOne
  • Wazuh Active Response as an explicitly experimental driver
  • Triggered from the incident or as a rule chain action, for example after a decoy alert
  • Duplicate protection: identical actions on the same target are rejected for fifteen minutes
  • Automated requests throttled to twenty per hour and tenant
  • Credentials stored encrypted and never displayed again, connection test per connector
  • HTTPS only, no redirects, known provider regions offered for selection
  • The containment timestamp on the incident is set automatically on first success
Result

The intervention sits where the incident sits: with a justification, a second person and a timestamp that later proves when the spread was stopped.

Experience Containment Actions live

Schedule a no-obligation demo – we will show you the module with your own use cases.