Acronis Advanced EDR Incident Response Guide | Threat Containment and Remediation

Acronis Advanced EDR Incident Response Actions

This document explains how to perform incident response actions using Acronis Advanced EDR, including endpoint isolation, threat removal, indicator management, incident closure, and documentation.

Platform: Acronis Cyber Protect Cloud


1. Isolate an Endpoint

Procedure

  1. Log in to the Acronis Cyber Protect Cloud console.
  2. Navigate to:

    Security → Incidents
  3. Open the required security incident.
  4. Select the affected endpoint.
  5. Choose:

    Isolate Device
  6. Confirm the isolation action.

Note: Endpoint isolation restricts network communication while allowing security management access for investigation.


2. Remove Endpoint Isolation

Procedure

  1. Navigate to:

    Devices → Security
  2. Select the isolated endpoint.
  3. Choose:

    Remove Isolation
  4. Confirm the action.
  5. Verify the endpoint reconnects to normal network communication.

3. Quarantine a Malicious File

Procedure

  1. Open the detected security incident.
  2. Navigate to the affected file details.
  3. Select:

    Quarantine
  4. Confirm the action.
  5. Verify the file status changes to quarantined.

Note: Quarantined files are isolated and prevented from executing.


4. Restore a File from Quarantine

Procedure

  1. Navigate to:

    Security → Quarantine
  2. Select the required file.
  3. Review the file details.
  4. Choose:

    Restore
  5. Confirm the restore action.

Note: Restore files only after confirming they are safe and not malicious.


5. Stop a Malicious Process

Procedure

  1. Open the affected security incident.
  2. Navigate to:

    Process Activity
  3. Identify the malicious process.
  4. Select:

    Stop Process
  5. Confirm the action.
  6. Review the endpoint activity for additional threats.

6. Perform Attack Rollback

Procedure

  1. Open the ransomware or malware incident.
  2. Review detected changes.
  3. Select:

    Rollback / Recover Changes
  4. Choose the affected files or system changes.
  5. Start the rollback operation.
  6. Monitor the recovery status.

Note: Attack rollback helps restore system changes caused by malicious activity.


7. Add an Indicator of Compromise (IOC)

Procedure

  1. Navigate to:

    Security → Indicators
  2. Select:

    Add Indicator
  3. Choose the indicator type:
    • File Hash
    • IP Address
    • URL
    • Domain
  4. Enter the IOC value.
  5. Configure the required action.
  6. Save the indicator.

8. Block a Malicious Hash

Procedure

  1. Navigate to:

    Security → Indicators
  2. Select:

    Add Indicator
  3. Choose:

    File Hash
  4. Enter the malicious hash value.
  5. Select the block action.
  6. Save the configuration.

Note: Hash blocking prevents known malicious files from executing.


9. Block a Malicious URL

Procedure

  1. Open the Indicators section.
  2. Select:

    Add Indicator
  3. Choose:

    URL
  4. Enter the malicious URL.
  5. Configure the block action.
  6. Save the indicator.

10. Block a Malicious IP Address

Procedure

  1. Navigate to:

    Security → Indicators
  2. Select:

    Add Indicator
  3. Choose:

    IP Address
  4. Enter the malicious IP address.
  5. Enable blocking.
  6. Save the configuration.

11. Close an EDR Incident

Procedure

  1. Navigate to:

    Security → Incidents
  2. Open the resolved incident.
  3. Review investigation details.
  4. Confirm remediation actions are completed.
  5. Select:

    Close Incident
  6. Enter the resolution status.
  7. Confirm closure.

12. Document an EDR Incident

Procedure

  1. Open the security incident.
  2. Add investigation notes including:
    • Incident summary
    • Detection details
    • Affected endpoints
    • Root cause
    • Actions performed
    • Recovery steps
    • Final resolution
  3. Attach relevant evidence if required.
  4. Save the incident documentation.
    • Related Articles

    • Acronis Advanced EDR Incident Investigation

      This document explains how to investigate security incidents using Acronis Advanced EDR, including reviewing alerts, analyzing attack timelines, examining endpoint activity, and investigating common security threats. Platform: Acronis Cyber Protect ...
    • Acronis Advanced EDR Configuration

      This document explains how to enable and configure Acronis Advanced Endpoint Detection and Response (EDR), including agent installation, protection plans, malware protection, antivirus scheduling, and security exclusions. Platform: Acronis Cyber ...
    • Acronis Advanced EDR Troubleshooting

      This document provides troubleshooting steps for common Acronis Advanced EDR issues, including agent connectivity problems, protection failures, scan issues, false positives, and endpoint performance concerns. Platform: Acronis Cyber Protect Cloud 1. ...