Skip to main content
File containment automatically (or manually) quarantines files when they are associated with malicious detections. If a detection matches a verdict rule with file containment actions configured, but the global file auto-containment setting is disabled, the detection will be escalated to your team. Containment is always enabled manually when reviewing a case and selecting Actions > Contain.
Auto-containment is not performed for detections from beta integrations. If the detection is generated by a beta integration, Wirespeed will skip automatic containment and escalate the case to your team instead. Manual containment remains available.

Containment Actions

Wirespeed takes the following action to contain a file:
  • Quarantine — removes the file from its original location and places it in quarantine, preventing execution

Uncontainment Actions

When a detection is resolved as benign, Wirespeed can automatically reverse containment:
  • Unquarantine — restores the file from quarantine back to its original location

Cooldown

To prevent repeated containment of the same file in rapid succession, Wirespeed enforces a 15-minute cooldown. If a file was contained within the last 15 minutes, additional auto-containment attempts will be skipped.