G DATA XDR

Quarantine

Artifacts that were classified as a potential threat during a security event are moved to Quarantine. This means the files are stored in encrypted form in a separate directory on your endpoint so that they can no longer cause any harm. The encrypted files are located …​

  • on Microsoft Windows endpoints: C:\ProgramData\G DATA\Agent\quarantine\storage.

  • on Linux and Mac endpoints: /var/lib/gdata/agent/quarantine/recovery.

Quarantine

In the Quarantine menu section, you can …​

  • view the details.

  • restore artifacts.

  • delete artifacts that are in Quarantine.

The toolbar

Quarantine toolbar G DATA XDR

Using the toolbar, you can search for artifacts, filter them, or show and hide columns.

Filter artifacts Filter

Filter artifacts G DATA XDR

If you do not want to display all artifacts in the list, you can filter the artifacts using the filter icon based on various criteria:

When the page is opened, artifacts that are older than one month are already hidden.

Column Filter Value

Status

equals (=)
does not equal (!=)

In Quarantine
Being restored
Restored
Being deleted
Deleted
Delete failed
Restore failed

Customer

contains
does not contain
equals
does not equal

String entered in Value (free text)

Endpoint

contains
does not contain
equals
does not equal

String entered in Value (free text)

Artifacts

contains

String entered in Value (free text)

Detections

contains

String entered in Value (free text)

Created

is before
is after
is between

Free input or calendar selection
Calendar selection

By clicking BtnFilterHinzu you can add additional filters.

When you add the first filter, you have the option to select the filter logic (AND or OR).

AND/OR selection

All additional filters are linked to each other using the filter logic selected first. A different selection is no longer possible at this point.

The filter window closes when you press the button Show results

The set filters are displayed next to the filter icon and can be reset by clicking the x.


Select columns tableColumnDisplayButton

Using the columns icon, you can show or hide the available columns.

Select columns G DATA XDR

Search artifacts searchButton

Using the search (magnifying glass), you can quickly and easily search for artifacts. Enter free text in the search field. The artifacts for which matches were found are then displayed.


The Quarantine overview

Quarantine overview

In the overview, existing artifacts are displayed in list form. Here you can see the most important information about an artifact in summarized form.

You can see…​

  • the status of the alert.

    • In Quarantine

    • Being restored

    • Restored

    • Being deleted

    • Deleted

    • Delete failed

    • Restore failed

      If it was not possible to restore an artifact, the artifact is stored unencrypted in the following directory on the endpoint:

      • on Microsoft Windows endpoints: C:\ProgramData\G DATA\Agent\quarantine\storage.

      • on Linux and Mac endpoints: /var/lib/gdata/agent/quarantine/recovery.

      Remember that after it has been restored, a file will be detected again by the G DATA Agenten if

  • the customer for which the detection occurred (G DATA partner feature).

  • the name of the endpoint on which the detection occurred.

  • the original path and the name of the artifact that was moved to Quarantine.

  • the name of the detection due to which the artifact was moved to Quarantine.

  • the created time of the detection.

  • an action bar for editing the artifact (details page, restore, delete artifact).

The actions in the Quarantine overview


Lupe = Open the artifact details page

Clicking the magnifying glass icon in the artifact overview row opens the details page of the Quarantine container.

Quarantine details page

Here you can see the artifact information in the Quarantine container at a glance.

Here you can see …​

  • the unique identification number of the alert with which the security event was reported.

    In this context, note the link icon at the end of the number Link Pfeil. This icon takes you to the underlying alert. Detailed information about the detection can provide further insights and may indicate additional actions required.

  • the created time of the detection.

  • the name of the endpoint on which the detection took place.

  • the name of the customer for which the detection took place ( Managed Service Provider).

  • the platform (operating system) on which the detection took place.

  • the status of the artifact

  • the name of the detection.

This tile also contains buttons you can use to …​

  • restore artifacts.

  • delete artifacts.

Depending on the artifact, the details page contains an additional File tile and/or Registry tile. Which tile you see depends on the reported artifact. Empty tiles are hidden.

Quarantine details tile File
Quarantine details tile Registry

SymbolWiederhserstellen = Restore artifact

Click Symbol Wiederherstellen in the Actions column of the artifact row.

The Restore dialog opens.

1

Wiederherstellung bestätigen

Click Wiederherstellen.

2

ArtefaktWiederherstellen

In the window that opens, you can see where the artifact will be returned to.

Use the checkbox (see screenshot) to select one of the following options:

  • whether you want to restore and set an Exclusion in one step (checkbox selected).

  • whether you only want to restore the artifact (checkbox cleared).

3

Click Weiter.

4a

Optional: the checkbox for setting the Exclusion is selected.

If the checkbox is selected, you are accessing the same function that you can use for creating the Exclusion manually.

Differences from creating Exclusions manually

The difference is that the required information is already defined. At this point, it is possible to expand the scope of the Exclusion and to increase the scope using placeholders.

For example, you can expand a file in the user directory of the user admin to all users with this directory:

Create Exclusion via alert

At the end, click Wiederherstellen und Ausnahme hinzufügen.

4b

If you have cleared the checkbox for setting Exclusions, click Artefakte wiederherstellen

The artifact is returned to its original location.

If it was not possible to restore an artifact, the artifact is stored unencrypted in the following directory on the endpoint:

  • on Microsoft Windows endpoints: C:\ProgramData\G DATA\Agent\quarantine\storage.

  • on Linux and Mac endpoints: /var/lib/gdata/agent/quarantine/recovery.

Keep in mind that after restoration, a file will be detected again by the G DATA Agent if


LoeschenMuelleimer = Delete artifact

By clicking the delete icon, or using the corresponding button on the details page, you can delete the artifact.