Block versus Quarantine Malware Module Settings (2024)

This website uses Cookies. By clicking Accept, you agree to the storing of cookies on your device to enhance your community experience. Read our Privacy Policy.
Click Preferences to customize your cookie settings.

Preferences

Unlock your full community experience!
  • Access exclusive content
  • Connect with peers
  • Share your expertise
  • Find support resources

Turn on suggestions

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.

Showing results for

Showonly | Search instead for

Did you mean:

Announcements

Options

Block versus Quarantine Malware Module Settings

‎10-20-202307:04 AM

Is there a greater benefit to enabling the Quarantine setting versus the Block setting across the different modules in the Cortex XDR Malware profile? It is my understanding that both/either will result in the expected protective action (i.e. a potential threat will not be allowed to execute).

0 LikesLikes

5 REPLIES 5

Block versus Quarantine Malware Module Settings (4)

abdrahman

L3 Networker

‎10-22-202307:06 PM

Dear@Joe_Botelho,

Thank you for reaching out to Live Community. Please note that if the setting is configured to Quarantine then the file detected will be not allowed to execute and will be kept in a designated path for further analysis.

However, when it comes to block mode, if a file is detected as malicious then it will be detected and destroyed and removed from the endpoint.

If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.

0 LikesLikes

Block versus Quarantine Malware Module Settings (5)

Antony_Chan

L2 Linker

‎10-24-202302:54 AM

@Joe_BotelhoBased on my understanding, block will only terminate the suspicious/malicious process a.k.a. causality chain. The files, configuration, code/script will remain in the affected system. In this case, the alert may re-occur until someone take remediation action against the system.

If you enable the option to quarantine the file - depending on the module and alert - it will remove the file and stored it in a sub-directory of Cortex XDR. Due to the file is no longer available, it will not be able to execute and hence alert will not appear again. However, analyst need to review the quarantined file and make sure it is not a false-positive. Otherwise, a file restoration is required.

AC

0 LikesLikes

Block versus Quarantine Malware Module Settings (6)

Joe_Botelho

L1 Bithead

‎01-22-202412:26 PM

Thank you for the responses. I think I am still not clear on whether it makes a difference to use block or quarantine in terms of protection. Block is designed prevent the execution of potentially malicious files/processes but so is quarantine. Right now, it seems that quarantine has the added step of moving the file into a sub-directory of XDR. But if you were to use the block setting, you are still protecting the endpoints. Please let me know if I am incorrect here.

0 LikesLikes

Block versus Quarantine Malware Module Settings (7)

JayGolf

Community Team Member

‎03-13-202402:07 PM

To clarify, the "Block and Quarantine Disabled" setting is designed to prevent the execution of the executable files but does not necessarily remove the files permanently. It effectively blocks the file from running but leaves the file intact.

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

‎03-14-202405:11 AM

Thank you@JayGolffor the clarification.

0 LikesLikes

Block versus Quarantine Malware Module Settings (9)

  • 1536 Views
  • 5 replies
  • 0 Likes

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!

Block versus Quarantine Malware Module Settings (2024)
Top Articles
How to Withdraw Crypto from Kucoin to Trust Wallet
Free Demo Trading Account In India - How to Open Online with ZERO Risk
Craigslist Cars And Trucks For Sale By Owner Indianapolis
La connexion à Mon Compte
Top 10: Die besten italienischen Restaurants in Wien - Falstaff
35105N Sap 5 50 W Nit
Pickswise the Free Sports Handicapping Service 2023
AB Solutions Portal | Login
Joe Gorga Zodiac Sign
Citi Card Thomas Rhett Presale
Rls Elizabeth Nj
Ohiohealth Esource Employee Login
South Ms Farm Trader
Charmeck Arrest Inquiry
Restaurants Near Paramount Theater Cedar Rapids
Belle Delphine Boobs
Dexter Gomovies
Cinebarre Drink Menu
NHS England » Winter and H2 priorities
Wausau Marketplace
Persona 4 Golden Taotie Fusion Calculator
The Tower and Major Arcana Tarot Combinations: What They Mean - Eclectic Witchcraft
Pearson Correlation Coefficient
Www Craigslist Madison Wi
Who is Jenny Popach? Everything to Know About The Girl Who Allegedly Broke Into the Hype House With Her Mom
SN100C, An Australia Trademark of Nihon Superior Co., Ltd.. Application Number: 2480607 :: Trademark Elite Trademarks
Lines Ac And Rs Can Best Be Described As
Tactical Masters Price Guide
Kristy Ann Spillane
1964 Impala For Sale Craigslist
Landing Page Winn Dixie
Royal Caribbean Luggage Tags Pending
Newsday Brains Only
The Wichita Beacon from Wichita, Kansas
آدرس جدید بند موویز
Why The Boogeyman Is Rated PG-13
Frcp 47
Frommer's Philadelphia & the Amish Country (2007) (Frommer's Complete) - PDF Free Download
Puretalkusa.com/Amac
Electronic Music Duo Daft Punk Announces Split After Nearly 3 Decades
Carteret County Busted Paper
Gamestop Store Manager Pay
Brauche Hilfe bei AzBilliards - Billard-Aktuell.de
Darkglass Electronics The Exponent 500 Test
Huntsville Body Rubs
Mlb Hitting Streak Record Holder Crossword Clue
Marine Forecast Sandy Hook To Manasquan Inlet
Bama Rush Is Back! Here Are the 15 Most Outrageous Sorority Houses on the Row
Sams La Habra Gas Price
Festival Gas Rewards Log In
Bomgas Cams
Dinargurus
Latest Posts
Article information

Author: Merrill Bechtelar CPA

Last Updated:

Views: 5720

Rating: 5 / 5 (70 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Merrill Bechtelar CPA

Birthday: 1996-05-19

Address: Apt. 114 873 White Lodge, Libbyfurt, CA 93006

Phone: +5983010455207

Job: Legacy Representative

Hobby: Blacksmithing, Urban exploration, Sudoku, Slacklining, Creative writing, Community, Letterboxing

Introduction: My name is Merrill Bechtelar CPA, I am a clean, agreeable, glorious, magnificent, witty, enchanting, comfortable person who loves writing and wants to share my knowledge and understanding with you.