Governed Response and Action History

Request, approve, track, and audit containment and remediation actions with governed response.

XDRShield Response Actions lets security operators request, approve, track, and audit containment and remediation steps including host isolation, process termination, and network or domain blocking. Each action follows an approval-gated workflow with full execution history and audit traceability.

Approval-gatedFull audit trailReversible response
Why it matters

Controlled containment is the difference between stopping a threat and creating a new operational incident.

Response actions give security teams a governed way to isolate endpoints, kill malicious processes, and block attacker infrastructure without losing oversight, reversibility, or audit evidence.

01

Controlled containmentIsolate compromised endpoints, kill malicious processes, and block command-and-control infrastructure with agent-enforced actions.
02

Approval-gated actionsRoute containment requests through an approval queue so designated approvers review and authorize actions before execution.
03

Full execution audit trailTrack requester, approver, target endpoint, action type, execution result, and timestamp for every response action.
04

Reversible responseRelease isolated hosts and restore normal network operation with a documented reversal action and verification steps.
Action lifecycle

From request to release, every response action follows a governed lifecycle.

Response actions move through a structured lifecycle: an operator requests an action, designated approvers review and authorize it, the endpoint agent executes it, the team verifies the outcome, and the action is either released or escalated. Each stage is recorded for audit and compliance.

  • Request an action including host isolate, process kill, or network/domain block from the response actions queue.
  • Approvers review pending requests, confirm the target endpoint, and authorize or reject the action before execution.
  • The endpoint agent executes the approved action and reports the result back to XDRShield.
  • Verify action status, review execution logs, validate endpoint behavior, and confirm management channel connectivity.
  • Release isolated hosts to restore normal network operation or escalate to further investigation and response.
XDRShield product screenshot showing governed response actions and action history
Response capabilities

What XDRShield Response Actions helps teams do.

Each capability supports a part of the response action workflow, from containment and remediation to approval governance, execution tracking, and audit traceability.

Host Isolate containment

Place a selected endpoint into a restricted network state to stop ongoing attacker activity, reduce lateral movement risk, and give the security team time to investigate safely.

Explore Host Isolate containment →

Process kill

Terminate malicious or suspicious processes on monitored endpoints with agent-enforced execution and outcome reporting.

Explore Process kill →

Network and domain blocking

Block known malicious IPs, CIDR ranges, domains, and URLs from reaching endpoints using policy-controlled network enforcement.

Explore Network and domain blocking →

Approval workflow gates

Route response actions through an approval queue where designated approvers review and authorize requested actions before execution to prevent accidental or unsafe containment.

Explore Approval workflow gates →

Release and restore

Release isolated hosts by removing containment rules and restoring saved network state so the endpoint can resume expected communication.

Explore Release and restore →

Audit history and traceability

Preserve requester, approver, target, action type, execution result, and timestamp for every response action to support compliance and post-incident review.

Explore Audit history and traceability →

Action types and when to use them

Choose the right response action for the operational situation.

Different threat scenarios call for different response actions. Understanding the purpose, operational impact, and reversibility of each action type helps teams choose the right containment or remediation step.

Action
Purpose
Operational Impact
Reversibility
Host Isolate
Place endpoint in restricted network state to stop attacker activity and lateral movement.
Business applications, internet access, and peer-to-peer connectivity may stop working until release.
Fully reversible using the Release action to remove isolation rules and restore network state.
Process Kill
Terminate a malicious or suspicious process running on a monitored endpoint.
The targeted process stops immediately. Dependent services or applications may be affected.
Not directly reversible. The process must be restarted manually or through a remediation workflow.
Network Block
Block known malicious IPs or CIDR ranges from reaching or communicating with endpoints.
Network traffic to or from blocked IPs is stopped. Legitimate shared infrastructure on the same IP may be affected.
Reversible by removing the network block rule from the endpoint policy.
Domain Block
Block known malicious domains and URLs from resolving or being accessed by endpoints.
DNS resolution and access to the blocked domain are stopped for all endpoints under the policy.
Reversible by removing the domain block rule from the endpoint policy.
File Quarantine
Move or mark a malicious file for containment so it cannot execute or spread.
The quarantined file becomes inaccessible. Applications depending on the file may fail.
Reversible by restoring the file from quarantine after verification and review.