The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Quarantine configuration in the policies

Prev Next

For a Sensor to automatically quarantine hosts that generate attacks, you need to enable Quarantine settings in the corresponding attack definitions. By default the Quarantine feature is disabled for all attacks. Regardless of whether you have enabled Quarantine in an attack, you can manually quarantine a host from the Attack Log.

You can enable Quarantine for attacks in the IPS and Reconnaissance policies. This applies to attacks from the Trellix Signature Set as well Custom Attack Definitions.

For ease of use, the Manager provides you various options to enable Quarantine for attacks:

  • Open multiple IPS or Reconnaissance policies. Then enable Quarantine for a specific attack or multiple attacks in these policies.

  • At the root admin domain, use the Master Attack Repository page to enable Quarantine for one or multiple attacks across IPS and Reconnaissance Policies.

Regarding attacks from the Signature Set, there are some for which Quarantine might not be relevant. Even if you enable Quarantine for such attacks, the Sensor does not quarantine hosts that generate these.

You can enable Quarantine for attacks from the Central Manager. Similar to other policy customization done at the Central Manager, it applies to the corresponding Central Manager policies used in all the Managers.