Four eyes, even under time pressure
Requesting and approving are separate rights held by separate people. When a rule chain requests the action, one approver suffices: the rule and the human are the two pairs of eyes.
Limit the damage before the analysis is finished
With ransomware, what counts is the time between the first alert and disconnecting the affected machine. Until now that step happened outside the platform: someone reads the alert, switches to the endpoint protection console or the directory and acts there. This module brings the intervention to where the incident is documented anyway, and gives it the same controls as any other intervention in the fleet: a second person, a justification, a log. An action is created as a request with a mandatory justification, waits for approval, is executed and, on first success, records the containment timestamp on the incident.
Requesting and approving are separate rights held by separate people. When a rule chain requests the action, one approver suffices: the rule and the human are the two pairs of eyes.
Every action can be reverted, and the reversal needs its own approval. Only the device acknowledgement turns it into “reverted”, not the click.
If the lookup finds no device or more than one, the action aborts and states the number. Disconnecting the wrong machine would be worse than disconnecting none.
Via your own agent for machines that have one, via the EDR console for everything else. Both are separate actions with their own reversal and do not cancel each other out.
The intervention sits where the incident sits: with a justification, a second person and a timestamp that later proves when the spread was stopped.
Schedule a no-obligation demo – we will show you the module with your own use cases.