Will you be ready when the next attack happens?
Cyberattacks are the new normal. It鈥檚 no longer a question of 鈥渋f鈥 an attack is going to occur, but 鈥渨hen.鈥 Your ability鈥攐r lack thereof鈥攖o quickly respond to a malware incident can make or break your business and client relationships.聽
To help you overcome this ongoing challenge to your network鈥檚 security, we鈥檝e added a Host Isolation feature to The 杏吧传媒 Security Platform.
Isolating infected hosts buys you invaluable time to plan and implement remediation and recovery actions, thus minimizing or completely stopping the spread of malware within your network. This is an especially powerful tool when an incident occurs outside of normal business hours鈥攁 common attack window for hackers and bad agents.聽
杏吧传媒鈥 Host Isolation feature provides users with the ability to quickly block incoming and outgoing network activity on infected hosts鈥攕ignificantly reducing the risk of malware spreading across your network.
The 杏吧传媒 SOC team determines when a 鈥楬ost-Isolation鈥-worthy incident has occurred, usually defined as the infection of malware that is known to quickly spread (e.g., Emotet, Trickbot, etc.). If an incident meets this criterion (and the account has enabled 鈥樞影纱-Managed鈥 Host Isolation), the following steps are implemented:聽
杏吧传媒 鈥榮elf-managed鈥 Host Isolation is also available from the Host Overview page. Here are some scenarios when you might want to manually isolate a host:
Account administrators can exclude entire organizations or specific hosts from 鈥樞影纱 Managed Host Isolation鈥 events. The feature is designed to accommodate your specific business security needs.
Host Isolation beta relied solely on Local Windows Group Policy (GPO). GPO-based isolation has limitations when hosts are not connected to their domain controller or for networks that utilize Domain-level GPO policy that can override Local GPO.聽
The new and improved 杏吧传媒 Host Isolation solution leverages the Windows Filtering Platform to manage the host firewall with a higher degree of efficacy. The rules applied by 杏吧传媒 block all inbound and outbound network connections unless the traffic is destined for a 杏吧传媒 service such as the agent or another essential service.聽
Host Isolation is triggered after a 杏吧传媒 SOC Analyst sends an incident report for an isolation-worthy incident or a partner manually clicks 鈥淚solate Host鈥 from the host overview page. These actions will send an isolation task to the host, and it will be processed within seconds if the host is online.
To learn more about Host Isolation, visit our .
Get insider access to 杏吧传媒 tradecraft, killer events, and the freshest blog updates.