G DATA XDR
Quarantine
Artifacts that were classified as a potential threat during a security event are moved to Quarantine. This means the files are stored in encrypted form in a separate directory on your endpoint so that they can no longer cause any harm. The encrypted files are located …
-
on Microsoft Windows endpoints: C:\ProgramData\G DATA\Agent\quarantine\storage.
-
on Linux and Mac endpoints: /var/lib/gdata/agent/quarantine/recovery.
In the Quarantine menu section, you can …
-
view the details.
-
restore artifacts.
-
delete artifacts that are in Quarantine.
The toolbar
Using the toolbar, you can search for artifacts, filter them, or show and hide columns.
Filter artifacts 
If you do not want to display all artifacts in the list, you can filter the artifacts using the filter icon based on various criteria:
|
When the page is opened, artifacts that are older than one month are already hidden. |
| Column | Filter | Value |
|---|---|---|
Status |
equals (=) |
In Quarantine |
Customer |
contains |
String entered in Value (free text) |
Endpoint |
contains |
String entered in Value (free text) |
Artifacts |
contains |
String entered in Value (free text) |
Detections |
contains |
String entered in Value (free text) |
Created |
is before |
Free input or calendar selection |
By clicking
you can add additional filters.
|
When you add the first filter, you have the option to select the filter logic (AND or OR).
All additional filters are linked to each other using the filter logic selected first. A different selection is no longer possible at this point. |
The filter window closes when you press the button

The set filters are displayed next to the filter icon and can be reset by clicking the x.
Select columns 
Using the columns icon, you can show or hide the available columns.
Search artifacts 
Using the search (magnifying glass), you can quickly and easily search for artifacts. Enter free text in the search field. The artifacts for which matches were found are then displayed.
The Quarantine overview
In the overview, existing artifacts are displayed in list form. Here you can see the most important information about an artifact in summarized form.
You can see…
-
the status of the alert.
-
In Quarantine
-
Being restored
-
Restored
-
Being deleted
-
Deleted
-
Delete failed
-
Restore failed
If it was not possible to restore an artifact, the artifact is stored unencrypted in the following directory on the endpoint:
-
on Microsoft Windows endpoints: C:\ProgramData\G DATA\Agent\quarantine\storage.
-
on Linux and Mac endpoints: /var/lib/gdata/agent/quarantine/recovery.
Remember that after it has been restored, a file will be detected again by the G DATA Agenten if
-
it is a resolved false detection.
-
-
-
the customer for which the detection occurred (G DATA partner feature).
-
the name of the endpoint on which the detection occurred.
-
the original path and the name of the artifact that was moved to Quarantine.
-
the name of the detection due to which the artifact was moved to Quarantine.
-
the created time of the detection.
-
an action bar for editing the artifact (details page, restore, delete artifact).
The actions in the Quarantine overview
= Open the artifact details page
Clicking the magnifying glass icon in the artifact overview row opens the details page of the Quarantine container.
Here you can see the artifact information in the Quarantine container at a glance.
Here you can see …
-
the unique identification number of the alert with which the security event was reported.
In this context, note the link icon at the end of the number
.
This icon takes you to the underlying alert. Detailed information about the detection can provide further insights and may indicate additional actions required. -
the created time of the detection.
-
the name of the endpoint on which the detection took place.
-
the name of the customer for which the detection took place ( Managed Service Provider).
-
the platform (operating system) on which the detection took place.
-
the status of the artifact
-
the name of the detection.
This tile also contains buttons you can use to …
-
restore artifacts.
-
delete artifacts.
Depending on the artifact, the details page contains an additional File tile and/or Registry tile. Which tile you see depends on the reported artifact. Empty tiles are hidden.
|
|
= Restore artifact
Click
in the Actions column of the artifact row.
The Restore dialog opens.
1 |
Click |
2 |
In the window that opens, you can see where the artifact will be returned to. Use the checkbox (see screenshot) to select one of the following options:
|
3 |
Click |
4a |
Optional: the checkbox for setting the Exclusion is selected. If the checkbox is selected, you are accessing the same function that you can use for creating the Exclusion manually. Differences from creating Exclusions manuallyThe difference is that the required information is already defined. At this point, it is possible to expand the scope of the Exclusion and to increase the scope using placeholders. For example, you can expand a file in the user directory of the user admin to all users with this directory:
At the end, click |
4b |
If you have cleared the checkbox for setting Exclusions, click
|
The artifact is returned to its original location.
|
If it was not possible to restore an artifact, the artifact is stored unencrypted in the following directory
on the endpoint:
Keep in mind that after restoration, a file will be detected again by the G DATA Agent if
|
= Delete artifact
By clicking the delete icon, or using the corresponding button on the details page, you can delete the artifact.



