Responding to alerts

NAVIGATION  Alerts >  Respond

SECURITY  To manage the quarantine:  Datto AV subscription with administrator or analyst-level platform access

SECURITY  To upload and enable extensions: Datto EDR subscription with administrator-level platform access

SECURITY  To deploy response extensions: Datto EDR subscription with analyst-level platform access

BEFORE YOU BEGIN   Response extensions are only available with an EDR subscription. If you do not have this service, you will only have access to the Quarantined Files page.

The Endpoint Security platform equips you with multiple options for immediate threat assessment and triage when an alert occurs. If you're a Datto AV subscriber, you'll have access to the quarantine feature, a powerful tool that enables isolation and containment of malicious activity on an endpoint. Datto EDR subscribers can deploy a wide variety of response extensions to affected devices, allowing for immediate remote remediation and recovery actions without the need to schedule a technician site visit.

the Endpoint Security platform provides you with multiple options to immediately triage the threat and stop the spread of malicious activity. If you're a Datto AV subscriber, you'll leverage the quarantine to do so. Datto EDR subscribers can leverage response extensions to do so.

This article describe how to manage quarantined files and activate and deploy response extensions. To learn about the Respond page, refer to Navigating the Respond page.

Datto AV

Datto AV includes a quarantine feature that enables you to isolate suspicious files for future analysis, decontamination, or deletion. Quarantined files persist within a dedicated holding area on the impacted endpoint's hard drive until you restore or remove them.

IMPORTANT  This feature is only available to Datto AV subscribers. Uninstalling the Datto AV agent permanently deletes the quarantine and all of its isolated files.

Datto EDR

Datto EDR subscribers have the ability to deploy executable files called "response extensions" to impacted endpoints to perform automated mitigation actions. We call this functionality "Click to Respond."

IMPORTANT   Response extensions are only available with an EDR subscription. If you do not have this service, you will only have access to the Quarantined Files page.

Good to know

For extensions and response options to work, the Endpoint Security agent must be active on the target machine. You can either permanently install the agent on the endpoint or initiate a new scan for its location to make the agent active before responding to the alert.

To learn more about creating and working with extensions, refer to Leveraging collection and response extensions. For information about creating suppression rules to reduce false-positive alerts, review our Suppressing alerts article.