Even if a threat has been re-mediated, you cannot be sure that there are no remnants that may impact performance (for example, registry keys, temp files, system changes, and so forth).
The purpose of this article is to guide SOC teams to effectively Rollback endpoints in case of a ransomware attack using Capture Client
What is Rollback?
Rollback function available with Capture Client restores the endpoint to the last available snapshot, undoing the changes made by the threat. Snapshots are created using Microsoft Windows Virtual Shadowcopy Services (VSS). This option is the most effective response for ransomware mitigation and disaster recovery.
Pre-requisites for Rollback
Policies -> Threat Protection -> Advanced settings -> Agent Configuration
Performing a Rollback for Ransomware Recovery
For every threat, there are multiple possible mitigation actions – Kill, Quarantine, Remediate, Rollback - that can be performed from the ‘THREAT DETAILS’ page on Capture Client Management Console. The Remediate and Rollback options are only available if the threat was detected by a behavioral engine.
NOTE: If ‘Rollback’ is forced without ‘Remediate’, it can restore files created by the threat.