What does an EDR's network-isolate action on a compromised host stop, and what does it not stop?
answer
- think about what the button touches
- the agent still phones home
- one host, not one intruder
- damage stopped, access not revoked
- persistence and stolen credentials survive it
basics
~20 sNetwork isolation cuts a host's traffic except the EDR agent's own channel, so an intruder loses interactive access from that machine. It kills no running process, removes no persistence, revokes no stolen credential, and touches nothing on any other host.
solid answer
~50 sIsolation is a network control on one machine. The EDR agent drops all inbound and outbound traffic except its own link to the management console, plus whatever the responder explicitly allowlists. That ends the intruder's interactive session from that host and stops it reaching anything else on the network, and it lets you keep working the box through live response. What it does not do is anything about the intruder themselves: processes they started keep running locally, scheduled tasks and services they planted are still there, credentials they harvested still work from anywhere else, and any other host they already own is untouched. Isolation is containment of one host, not eradication of an intrusion — and it is loud, because their session drops the moment you click it. It also freezes your own visibility: whatever they were about to do next, you will not see.
go deeper
Be ready to state plainly that isolation is a network control on one machine, that the EDR agent keeps its own channel, and that it removes neither persistence nor stolen credentials.
Explain the mechanics: where the filter is applied, why the management channel is exempt, what live response can still do, and why a local process can still cause damage after the cut.
Show the judgment around the button — that isolating goes loud, freezes your scoping, and leaves an unfinished eradication phase behind, so you sequence collection and credential work around it rather than treating it as the end.
Own the framing that containment scope is a design decision: which assets can be isolated unilaterally, which need an owner's agreement, and what the response plan promises about that before an incident starts.
## What the control actually is "Network isolation" (also called network containment or host quarantine, depending on the EDR vendor) is a command sent to the endpoint agent that installs a local network filter. From that moment the host may talk to essentially one destination — the EDR's own management infrastructure — plus any addresses the responder adds to an allowlist. Everything else, in both directions, is dropped at the host. The carve-out for the agent's channel is the point of the design. It means the machine is cut off from the estate and from the internet while you keep full live-response capability: you can still list processes, pull files, capture a memory image, collect registry hives and run collection scripts over that channel. A responder who thinks isolation ends their access to the box has misunderstood the control. ## What it stops - The intruder's interactive session from that host, immediately. - Outbound command-and-control and any data transfer that has not already completed. - Lateral movement *from* that host to file servers, domain controllers, or anything else reachable on the network. - The host as a launch point. It is a boundary drawn around one machine. ## What it does not stop This is the half candidates skip, and it is where the marks are. - **Local execution.** The machine is still running. A process the intruder started before you isolated keeps executing: it can still encrypt or wipe local data, still clear logs, still delete its own artefacts. Isolation is not a kill switch. - **Persistence.** Scheduled tasks, services, run keys, WMI subscriptions and planted binaries are all still on disk. Containment and eradication are different phases; isolation is squarely the first one. - **Credentials.** Anything they harvested — a password, a Kerberos ticket, a refresh token, an API key, a cloud access key — remains valid and usable from any machine on earth. Cutting the network on the host where the credential was stolen does nothing to the credential. - **Their other footholds.** If they own three hosts and you isolate one, they own two. If their access path is a management agent or a cloud console rather than that specific machine, isolating it removes almost nothing. ## The cost you pay Two costs, and both matter for the isolate-or-watch decision this sits inside. First, **it tells them.** Their session drops with no warning. A capable operator reads that as "detected" and behaves accordingly, which may mean going quiet on the footholds you have not found yet, or moving fast to finish what they came for. Second, **it freezes your understanding.** Everything you know about their objective, their next target and which credentials they are actively using came from watching them work. After isolation you have artefacts — a memory image, a disk, logs — which tell you about the past on one machine. They tell you nothing about where the operator was heading. Scope is the hardest thing to establish in an intrusion, and live activity is the cheapest way to establish it. Third, there is a real user attached to the machine. Somebody's workstation just went dark, mid-task. That is a cost, and on a revenue-bearing system it is a cost somebody else is entitled to argue about. ## Reading it correctly The direction of every claim matters. A quiet host after isolation proves the host cannot reach the network. It does not prove the intrusion is over, does not prove persistence is gone, and does not prove the intruder has lost access to the estate. The absence of further activity from a machine you deliberately silenced is not evidence of anything except that your control worked. So isolation is best understood as: *stop the bleeding from this one wound, buy time, keep your forensic access, accept that you have gone loud and gone blind.* Whether that trade is right depends on how much scope you still do not understand — which is the whole isolate-or-watch argument.
- After you isolate the host, all the intruder's activity disappears from your telemetry. Why is that not evidence they are gone?Because you caused it. The host can no longer reach the network, so of course nothing more appears from it. That says nothing about credentials they already stole, other hosts they already own, or persistence still sitting on the machine. Silence from a source you deliberately muted is not a finding. Proving they are gone needs an estate-wide persistence hunt and a watch for re-entry, not the absence of noise from a quarantined box.
- What can you still collect from a host once it is network-isolated?Everything you could collect before, because the EDR agent's channel is deliberately exempt from the isolation filter. Live response still gives you a process list, network connection table, memory capture, file collection, registry hives and scheduled-task enumeration. Collect volatile state first — memory and current connections — since the host is still running and a live local process can still destroy things.
- Does isolating the host preserve evidence?Partly. It stops remote tampering and stops further exfiltration, which helps. But the machine keeps running: a local process the intruder already started can still delete files, and every minute of uptime overwrites more of the memory and disk state you may want. If the evidence matters, capture volatile state promptly after isolating rather than treating isolation as a pause button.
Isolating a host is like sealing the room the burglar is standing in. They cannot take anything else out, and you can no longer see which door they were reaching for — and the rest of the house still has their copied keys.
saying these in an interview costs you the question
- Says isolation kills the intruder's processes on the host
- Believes isolation removes persistence or ends the incident
- Thinks the analyst loses all access to an isolated host
- Treats silence after isolation as proof the intrusion is over
- Assumes stolen credentials stop working once the host is cut off