Managing file quarantine
When a malicious operation occurs in your pool, SES Evolution makes it possible to detect suspicious files and quarantine them while they are being analyzed. Quarantined files can no longer be run, or cause any damage to the workstation. After the analysis, if the files are found to be harmless, you can restore them to their original location.
You can establish a list of folders to exclude. The files that they contain will be protected from quarantine.
Quarantine and restore operations are logged in Agent logs.
You need to hold the Remediation-Modify permission to quarantine and restore files.
-
Select the Responses > Quarantine menu and click on the Parameters tab.
In the Predefined exclusions section, some system folders are excluded by default, as it would be inappropriate to quarantine their content. Folders are displayed in the form of EsaRoots variables. -
Click on Edit in the upper banner.
-
Under Custom exclusions, enter the path to the folder containing the content you wish to protect. Generic characters are not allowed.
-
Enable the Recursive option if the content of sub-folders needs to be protected as well.
-
In the Owner field, select one of the Windows groups that owns the file if necessary, or enter a specific SID.
-
Click on to validate the line.
-
Add as many paths as needed and click on Save.
You can temporarily disable exclusions by unselecting the checkboxes on the left side of the lines.
Files can be quarantined:
-
Automatically when a protection rule that you have configured is triggered. For more information on rule configuration, refer to Defining access control rules.
-
Manually during remediation. For more information, see the section Managing remediation tasks.
Files located on a network share will not be quarantined.
During quarantine, files will be moved to the agent's local folder: C:\ProgramData\Stormshield\SES Evolution\Agent\Quarantine. Access to this folder is not allowed, even to administrators, and the files that it contains are encrypted.
- Select the Responses > Quarantine menu and the General tab to display the list of quarantined files.
- If necessary, use the Quarantine status and Agent group filters to narrow down the list. The statuses can either be Quarantined or Pending restoration.
- Select a file in the list to display information on the file and the agent concerned in the panel on the right.
After the analysis, if you consider the file harmless and a false positive:
-
Add an exception on the log and deploy the changes on all agents, so that the file will no longer be detected as malicious,
-
Restore it to its original location. The file will be restored exactly as it was, with the same ACLs and same alternate data streams.
To restore the file:
-
Select the Responses > Quarantine menu and the General tab.
-
Right-click on the file to restore and select Restore selection.
The Restore quarantined files window appears. All quarantined files with the same hash will be listed and selected for restoration. -
Enable the option Overwrite existing file if the same file already exists in the original location and you wish to replace it.
- If necessary, use the search field or the Quarantine status and Agent group filters to narrow down the list. The statuses can either be Quarantined or Pending restoration.
- Unselect any files that you would like to keep quarantined. All files with the same hash will always be restored at the same time at their respective locations.
- Click on Restore.
A restoration task will be created and the status of the files will switch to Pending restoration. The files will then be moved from the quarantine repository to their original locations, and disappear from the Quarantine panel.
Files are kept in the quarantine repository for 40 days before they are automatically deleted. In addition, if the volume of the quarantine repository exceeds 1 GB, the oldest files will be automatically deleted to make space for new files.
You can also choose to manually remove files from the Quarantine panel. In this case, the files will no longer be displayed, but will remain on disk in the quarantine repository. They will then be automatically deleted after 40 days, or if the 1 GB limit is exceeded.
- Select the Responses > Quarantine menu and the General tab.
- Right-click on the file you want to delete, and select Delete selection.
- Confirm deletion.
The file will no longer appear in the list.
Quarantined files will automatically be deleted when the SES Evolution agent is uninstalled.