Skip to main content
Endpoint remediation automatically (or manually) isolates endpoints when they are associated with malicious detections. If a detection matches a verdict rule with endpoint remediation actions configured, but endpoint auto-remediation is disabled globally or blocked by group policy, the detection will be escalated to your team.
Auto-remediation is not performed for detections from beta integrations. If the detection is generated by a beta integration, Wirespeed will skip automatic remediation and escalate the case to your team instead. Manual remediation remains available.

Remediation Actions

Wirespeed can take the following actions to remediate an endpoint:
  • Isolate Endpoint — disconnect the endpoint from the network
  • Lock Device — remotely lock the device screen
Which actions appear in the UI and run for a detection depend on the connected EDR or MDM integration and the actions selected on the matching verdict rule.

Release Actions

When a detection is resolved as benign, Wirespeed can automatically reverse endpoint remediation:
  • Unisolate Endpoint — reconnect the endpoint to the network
  • Unlock Device — unlock the device screen

Critical Assets and groups

Critical Assets and other endpoint classifications are managed through Groups. The built-in Critical Asset, Domain Controller, and Server groups have remediation disabled by default. Manual remediation from the case Actions menu remains available. Review how critical assets are represented in your environment before enabling remediation on those groups.

Supported integrations

Endpoint remediation and release actions are available through connected EDR and MDM integrations, including: Each integration supports a subset of the actions above. Isolate is provided by EDR integrations; Lock Device is provided by MDM integrations such as JumpCloud and Kandji. The Remediate or Release dialog only shows actions your connected integration can perform.