Skip to main content

Isolate an endpoint

The Isolate endpoint Action cuts an endpoint off the network while keeping it reachable by Huntbase, so you can still query it, use live response on it and release it.

Beta

This feature is currently rolling out and may not be enabled for your organization.

What isolation blocks​

Everything except:

  • traffic to Huntbase's control plane, so Scout keeps checking in;
  • loopback;
  • DHCP, so the endpoint keeps its address;
  • any extra addresses you allow with the Allow IPs parameter, for example a response jump host.
PlatformHow it's applied
LinuxAn nftables table, huntbase_isolation, or a dedicated iptables chain where nftables isn't installed.
WindowsWindows Firewall rules in the group Huntbase Isolation, with inbound and outbound blocked on every profile. The previous settings are saved for release.
macOSA pf anchor, com.huntbase.isolation. The system pf state is restored on release.

Isolate​

  1. Open the endpoint and choose Respond, then Isolate endpoint under Saved Actions, or run Isolate endpoint from Library › Actions on several endpoints.
  2. Give a reason and run it. Isolation needs two people by default: the run waits until a second person approves it in Activity › Actions.
  3. When the run succeeds, the endpoint's header shows Isolated.

Before it cuts anything, the endpoint makes sure it already has the release script cached, because it can't download anything once isolated. After applying the rules, it checks it can still reach Huntbase, and it undoes the isolation within a minute if it can't.

Check isolation is enforced​

A Group Policy or MDM-managed firewall can override the rules. To check, query the endpoint with the isolation-status query script:

SELECT json_extract(data, '$.isolated') AS isolated,
json_extract(data, '$.enforced') AS enforced,
json_extract(data, '$.overridden_by') AS overridden_by
FROM scout_exec WHERE script = 'isolation-status';

If enforced is false, treat the endpoint as not isolated.

Release​

Run Release endpoint from the endpoint's Respond menu (under Saved Actions), or from the Isolate endpoint Action's Endpoints tab. It doesn't need approval.

Isolation never releases on its own. Releasing a machine that is still compromised on a timer is the worse mistake. Instead, the person who isolated an endpoint and its approvers get an Inbox reminder after 24 hours, then daily while it stays isolated.