Security Operations
Respond to endpoint threats across devices and accounts
Cantina responds to your EDR detection, removes malicious files, and checks whether the user's credentials were used on other systems.
Follow an endpoint compromise into the connected account
An endpoint alert can involve both a compromised machine and stolen credentials. Cantina handles the device response and investigates the account associated with it, so your team can determine whether the attacker accessed anything else.
Contain the host and investigate credential use
- 01
Isolate the host
Contain the device identified by the EDR detection.
- 02
Clean up
Remove malicious artifacts left on the machine.
- 03
Block the file
Prevent the same malicious file from running elsewhere in the fleet.
- 04
Check credential use
Investigate whether the account was used on other systems.
LT-4471 — j.okafor
malware.exec · high severity
-
Host isolated
LT-4471 · contained
-
Artifacts removed
3 files quarantined
-
File blocked fleet-wide
hash blocked · 812 hosts
-
Credential use checked
1 reuse found · okta
Coordinate host isolation, cleanup, and account checks
-
CrowdStrike detections
Start the response from an endpoint alert.
-
Device containment and cleanup
Isolate the host and remove the files left by the attack.
-
Fleet-wide file blocking
Apply the block beyond the original device.
-
Account investigation
Check for credential use that could indicate a wider compromise.
What security teams say about Cantina
Cantina is the first platform we have used that carries the work through from finding an issue to driving the fix, and it lets my team operate like one far larger than it is. We keep finding new uses for it across our security program.
Matt Mock
Chief Information Security Officer
See how Cantina responds beyond the affected device
Follow the host isolation, cleanup, file block, and account investigation in a demo.