Malwarebytes Endpoint Detection and Response includes Endpoint Isolation, which temporarily stops threats from spreading between endpoints by restricting their communication or access. An isolated endpoint can still communicate with the console and run Malwarebytes processes. Super Admins and Administrators can isolate endpoints that have had a Threat Scan.
For Endpoint Isolation usage requirements, see Minimum requirements for Malwarebytes Nebula platform.
Types of isolation
There are three different isolation types. They may be enabled separately or combined to increase isolation. The three isolation types are:
- Network Isolation: Prevent the endpoint from communicating with other devices on your network.
- Process Isolation: Restrict which processes can run on the endpoint and prevent processes from interacting.
- Desktop Isolation: Prevent end users from accessing the endpoint.
With Process Isolation enabled, only Privileged Processes are allowed to launch on the endpoint. Privileged Processes belong to one of these types:
- Predefined (hardcoded) processes: Currently there are two predefined processes: CONSENT.exe, necessary to execute UAC elevated processes; and CSRSS.EXE which is a critical system process.
- Processes digitally signed by Malwarebytes: These are allowed to run unrestricted on isolated endpoints.
- Processes spawned by other Privileged Processes: A process with a privileged parent process is also privileged. Privileged child process may create more privileged child processes.
Isolate endpoints
Before you can isolate an endpoint, Malwarebytes must run a Threat Scan on the system. This is necessary to install plugins for the Endpoint Agent. When the scan finishes, you can isolate the endpoint.
Isolation is cumulative. If you select an isolated endpoint and apply another type of isolation, both isolation types will be applied.
- Go to Endpoints.
- Select which endpoints you want to isolate.
- In the top right of the screen, select Actions > Isolate Endpoint(s).
- Confirm the types of isolation you want, and click YES. All isolation types are enabled by default.
Change isolation type
To change the isolation type applied to an endpoint, you must either:
- Add additional isolation types
- Remove all isolation and then apply the isolation types needed
Remove endpoint isolation
You can remove endpoints from isolation on the Endpoints screen. Removing an endpoint from isolation turns off all isolation types.
- Go to Endpoints.
- Select the endpoints you want to remove from isolation.
- In the top right of the screen, select Actions > Remove Isolation.
- The endpoint will be removed from isolation and automatically reboot. You may lose any unsaved work.
Customize endpoint isolation alerts (Windows only)
You can customize the message displayed on endpoints when they are isolated. This is optional, and is changed at the policy level.
- Go to Settings > Policies > Select a policy > Windows > Settings > Endpoint Detection & Response (EDR) Settings > ENDPOINT ISOLATION (EDR).
- Enter custom text in the Isolation Title and Isolation Message fields, or click Use Default Message to restore the default.
- You may upload a BMP image to be displayed along with the message. Drag an image file onto the upload area or click CHOOSE A FILE to select an image.
- Click SAVE to save changes. The new isolation message will be shown for future endpoint isolations. It does not affect currently-isolated endpoints.
Return to the Malwarebytes Nebula platform Administrator Guide.