Acronis Advanced EDR Incident Response Actions
1. Isolate an Endpoint
Procedure
-
Log in to the Acronis Cyber Protect Cloud console.
Navigate to:
-
Open the required security incident.
-
Select the affected endpoint.
Choose:
-
Confirm the isolation action.
Note: Endpoint isolation restricts network communication while allowing security management access for investigation.
2. Remove Endpoint Isolation
Procedure
Navigate to:
-
Select the isolated endpoint.
Choose:
-
Confirm the action.
-
Verify the endpoint reconnects to normal network communication.
3. Quarantine a Malicious File
Procedure
-
Open the detected security incident.
-
Navigate to the affected file details.
Select:
-
Confirm the action.
-
Verify the file status changes to quarantined.
Note: Quarantined files are isolated and prevented from executing.
4. Restore a File from Quarantine
Procedure
Navigate to:
-
Select the required file.
-
Review the file details.
Choose:
-
Confirm the restore action.
Note: Restore files only after confirming they are safe and not malicious.
5. Stop a Malicious Process
Procedure
-
Open the affected security incident.
Navigate to:
-
Identify the malicious process.
Select:
-
Confirm the action.
-
Review the endpoint activity for additional threats.
Procedure
-
Open the ransomware or malware incident.
-
Review detected changes.
Select:
-
Choose the affected files or system changes.
-
Start the rollback operation.
-
Monitor the recovery status.
Note: Attack rollback helps restore system changes caused by malicious activity.
7. Add an Indicator of Compromise (IOC)
Procedure
Navigate to:
Select:
Choose the indicator type:
-
File Hash
-
IP Address
-
URL
-
Domain
-
Enter the IOC value.
-
Configure the required action.
-
Save the indicator.
8. Block a Malicious Hash
Procedure
Navigate to:
Select:
Choose:
-
Enter the malicious hash value.
-
Select the block action.
-
Save the configuration.
Note: Hash blocking prevents known malicious files from executing.
9. Block a Malicious URL
Procedure
-
Open the Indicators section.
Select:
Choose:
-
Enter the malicious URL.
-
Configure the block action.
-
Save the indicator.
10. Block a Malicious IP Address
Procedure
Navigate to:
Select:
Choose:
-
Enter the malicious IP address.
-
Enable blocking.
-
Save the configuration.
11. Close an EDR Incident
Procedure
Navigate to:
-
Open the resolved incident.
-
Review investigation details.
-
Confirm remediation actions are completed.
Select:
-
Enter the resolution status.
-
Confirm closure.
12. Document an EDR Incident
Procedure
-
Open the security incident.
Add investigation notes including:
-
Incident summary
-
Detection details
-
Affected endpoints
-
Root cause
-
Actions performed
-
Recovery steps
-
Final resolution
-
Attach relevant evidence if required.
-
Save the incident documentation.
Related Articles
Acronis Advanced EDR Incident Investigation
This document explains how to investigate security incidents using Acronis Advanced EDR, including reviewing alerts, analyzing attack timelines, examining endpoint activity, and investigating common security threats. Platform: Acronis Cyber Protect ...
Acronis Advanced EDR Configuration
This document explains how to enable and configure Acronis Advanced Endpoint Detection and Response (EDR), including agent installation, protection plans, malware protection, antivirus scheduling, and security exclusions. Platform: Acronis Cyber ...
Acronis Advanced EDR Troubleshooting
This document provides troubleshooting steps for common Acronis Advanced EDR issues, including agent connectivity problems, protection failures, scan issues, false positives, and endpoint performance concerns. Platform: Acronis Cyber Protect Cloud 1. ...