The Quarantine Device Alert Action prevents suspicious activity and malware on a device from affecting the rest of your network. The quarantined device can communicate with Carbon Black Cloud only until it is removed from quarantine.

Note: See also Devices API.

Configuration:

Device ID Field
The field name in the search results that contains the Device ID to quarantine.