杏吧传媒

Search
searchclose icon

Evolving the Hunt: Host Isolation for Smarter Defense

Glitch effectGlitch effectGlitch effect
Glitch banner

Will you be ready when the next attack happens?

Cyberattacks are the new normal. It鈥檚 no longer a question of 鈥渋f鈥 an attack is going to occur, but 鈥渨hen.鈥 Your ability鈥攐r lack thereof鈥攖o quickly respond to a malware incident can make or break your business and client relationships.聽

To help you overcome this ongoing challenge to your network鈥檚 security, we鈥檝e added a Host Isolation feature to The 杏吧传媒 Security Platform.

Isolating infected hosts buys you invaluable time to plan and implement remediation and recovery actions, thus minimizing or completely stopping the spread of malware within your network. This is an especially powerful tool when an incident occurs outside of normal business hours鈥攁 common attack window for hackers and bad agents.聽

What Is Host Isolation?

杏吧传媒鈥 Host Isolation feature provides users with the ability to quickly block incoming and outgoing network activity on infected hosts鈥攕ignificantly reducing the risk of malware spreading across your network.

But what is 杏吧传媒-Managed Host Isolation?

The 杏吧传媒 SOC team determines when a 鈥楬ost-Isolation鈥-worthy incident has occurred, usually defined as the infection of malware that is known to quickly spread (e.g., Emotet, Trickbot, etc.). If an incident meets this criterion (and the account has enabled 鈥樞影纱-Managed鈥 Host Isolation), the following steps are implemented:聽

  • SOC sends an incident report to the affected account, which triggers an isolation event for the associated 杏吧传媒-managed host
  • The host is isolated as soon as the agent on the host processes the isolation task鈥攚hich takes just seconds due to
  • Network connectivity checks are conducted to verify that the host is isolated
  • The account administrator can approve the provided steps associated with the incident report or manually remediate the incident
  • The host remains in isolation until the incident report is resolved
  • Once resolved, a release task is sent to the agent to restore network connectivity

杏吧传媒 鈥榮elf-managed鈥 Host Isolation is also available from the Host Overview page. Here are some scenarios when you might want to manually isolate a host:

  • You have a host excluded from '杏吧传媒-Managed' Host Isolation due to certain business continuity concerns, but you now have decided that the risk posed by an ongoing incident is significant enough to isolate the computer.聽
  • You use another security product that identified a threat, but it lacks network isolation functionality鈥攕o you leverage 鈥榮elf-managed鈥 Host Isolation via the 杏吧传媒 portal.聽

Account administrators can exclude entire organizations or specific hosts from 鈥樞影纱 Managed Host Isolation鈥 events. The feature is designed to accommodate your specific business security needs.

How Does 杏吧传媒 Isolate a Host?

Host Isolation beta relied solely on Local Windows Group Policy (GPO). GPO-based isolation has limitations when hosts are not connected to their domain controller or for networks that utilize Domain-level GPO policy that can override Local GPO.聽

The new and improved 杏吧传媒 Host Isolation solution leverages the Windows Filtering Platform to manage the host firewall with a higher degree of efficacy. The rules applied by 杏吧传媒 block all inbound and outbound network connections unless the traffic is destined for a 杏吧传媒 service such as the agent or another essential service.聽

How Long Does It Take for a Host to Be Isolated?

Host Isolation is triggered after a 杏吧传媒 SOC Analyst sends an incident report for an isolation-worthy incident or a partner manually clicks 鈥淚solate Host鈥 from the host overview page. These actions will send an isolation task to the host, and it will be processed within seconds if the host is online.

To learn more about Host Isolation, visit our .

Share

Sign Up for 杏吧传媒 Updates

Get insider access to 杏吧传媒 tradecraft, killer events, and the freshest blog updates.

By submitting this form, you accept our Terms of Service & Privacy Policy
Oops! Something went wrong while submitting the form.
杏吧传媒 at work