G DATA XDR

Restoring artifacts from quarantine

Click Quarantine, and then

search or filter the row with the artifact that you want to restore.
Filter artifacts Filter

Filter artifacts G DATA XDR

If you do not want to display all artifacts in the list, you can filter the artifacts using the filter icon based on various criteria:

When the page is opened, artifacts that are older than one month are already hidden.

Column Filter Value

Status

equals (=)
does not equal (!=)

In Quarantine
Being restored
Restored
Being deleted
Deleted
Delete failed
Restore failed

Customer

contains
does not contain
equals
does not equal

String entered in Value (free text)

Endpoint

contains
does not contain
equals
does not equal

String entered in Value (free text)

Artifacts

contains

String entered in Value (free text)

Detections

contains

String entered in Value (free text)

Created

is before
is after
is between

Free input or calendar selection
Calendar selection

By clicking BtnFilterHinzu you can add additional filters.

When you add the first filter, you have the option to select the filter logic (AND or OR).

AND/OR selection

All additional filters are linked to each other using the filter logic selected first. A different selection is no longer possible at this point.

The filter window closes when you press the button Show results

The set filters are displayed next to the filter icon and can be reset by clicking the x.


Search artifacts searchButton

Using the search (magnifying glass), you can quickly and easily search for artifacts. Enter free text in the search field. The artifacts for which matches were found are then displayed.


Click Symbol Wiederherstellen in the Actions column of the artifact row.

The Restore dialog opens.

1

Wiederherstellung bestätigen

Click Wiederherstellen.

2

ArtefaktWiederherstellen

In the window that opens, you can see where the artifact will be returned to.

Use the checkbox (see screenshot) to select one of the following options:

  • whether you want to restore and set an Exclusion in one step (checkbox selected).

  • whether you only want to restore the artifact (checkbox cleared).

3

Click Weiter.

4a

Optional: the checkbox for setting the Exclusion is selected.

If the checkbox is selected, you are accessing the same function that you can use for creating the Exclusion manually.

Differences from creating Exclusions manually

The difference is that the required information is already defined. At this point, it is possible to expand the scope of the Exclusion and to increase the scope using placeholders.

For example, you can expand a file in the user directory of the user admin to all users with this directory:

Create Exclusion via alert

At the end, click Wiederherstellen und Ausnahme hinzufügen.

4b

If you have cleared the checkbox for setting Exclusions, click Artefakte wiederherstellen

The artifact is returned to its original location.

If it was not possible to restore an artifact, the artifact is stored unencrypted in the following directory on the endpoint:

  • on Microsoft Windows endpoints: C:\ProgramData\G DATA\Agent\quarantine\storage.

  • on Linux and Mac endpoints: /var/lib/gdata/agent/quarantine/recovery.

Keep in mind that after restoration, a file will be detected again by the G DATA Agent if