Host Lockdown (EDR)
EDR Host Lockdown Information:
What is Host Lockdown?
Why is disabling a host necessary during a security investigation?
How does Host Lockdown work?
How does a host get locked down?
How do I manually lockdown a host?
How do I automatically lockdown a host?

Where can I check the lockdown status of a host?
If a host gets locked down, will existing/open sessions be terminated?
Once a host has been locked down, how can host isolation be removed?
If I update my automatic Lockdown thresholds, will all hosts be re-evaluated?
Is there API support for Host Lockdown?
If a host is isolated outside of Detect (via EDR) how does that appear in Detect?
Will the end user be notified when their host is locked down?
Will Detect administrators be notified when a host is locked down?
Where can I see a sample syslog notification for Lockdown?
Host Lockdown Sample Syslog
Can I use advanced search to pull information on isolated hosts?
Last updated
Was this helpful?
