File containment automatically (or manually) quarantines files when they are associated with malicious detections. If a detection matches a verdict rule with file containment actions configured, but the global file auto-containment setting is disabled, the detection will be escalated to your team. Containment is always enabled manually when reviewing a case and selecting Actions > Contain.Documentation Index
Fetch the complete documentation index at: https://docs.wirespeed.co/llms.txt
Use this file to discover all available pages before exploring further.
Auto-containment is not performed for detections from beta integrations. If the detection is generated by a beta integration, Wirespeed will skip automatic containment and escalate the case to your team instead. Manual containment remains available.
Containment Actions
Wirespeed takes the following action to contain a file:- Quarantine — removes the file from its original location and places it in quarantine, preventing execution
Uncontainment Actions
When a detection is resolved as benign, Wirespeed can automatically reverse containment:- Unquarantine — restores the file from quarantine back to its original location

