Quarantine is a security measure that isolates suspicious or malicious files, emails, or devices to prevent threats from spreading while allowing further analysis.
Quarantine in cybersecurity is the practice of isolating suspicious or confirmed malicious artifacts—files, emails, endpoints, or network segments—to prevent threat propagation while preserving evidence for analysis. Unlike deletion, quarantine maintains the artifact in a restricted state where it cannot execute or communicate, enabling security teams to investigate and determine appropriate remediation actions.
Email quarantine intercepts messages flagged by spam filters, malware scanners, or data loss prevention policies before delivery to user inboxes. Quarantined messages are stored in a secure repository where administrators or authorized users can review, release, or permanently delete them. Modern email security platforms apply machine learning classification with configurable sensitivity thresholds and user notification policies.
When antivirus software quarantines a file, it moves the file to an encrypted, restricted storage location and modifies file permissions to prevent execution. The original file path is recorded for potential restoration. The quarantine container prevents the malware from activating while preserving the sample for signature submission, threat intelligence correlation, and forensic investigation by security analysts.
Network quarantine isolates compromised or non-compliant endpoints by restricting their network access to remediation resources only. Technologies like 802.1X network access control and software-defined networking dynamically move infected hosts to quarantine VLANs. This containment prevents lateral movement while maintaining enough connectivity for the device to receive patches and security updates.
Quarantine preserves suspicious artifacts in a restricted state for analysis, while deletion permanently removes them. Quarantine enables false positive recovery, malware sample analysis, and forensic evidence preservation. Deletion risks losing critical threat intelligence and makes recovery impossible if the detection was incorrect. Best practice favors quarantine with time-based automatic deletion policies.
Network Access Control implements device quarantine by evaluating endpoint compliance posture during authentication. Devices failing health checks—missing patches, outdated antivirus, or policy violations—are placed in quarantine networks with restricted access. These quarantine segments typically allow only access to patch management servers, antivirus update sources, and helpdesk resources until compliance is restored.
Quarantine serves as the primary containment mechanism in incident response, limiting blast radius while investigations proceed. Incident responders quarantine affected endpoints, isolate compromised network segments, and contain suspicious emails to prevent further compromise. This buys critical time for forensic analysis, indicator extraction, and remediation planning without the evidence destruction that immediate deletion causes.
Configure quarantine policies with clear retention periods, automated notification workflows, and role-based review permissions. Define escalation procedures for quarantined items requiring urgent analysis. Implement automated submission of quarantined samples to sandbox environments and threat intelligence platforms. Establish regular review cadences to prevent quarantine storage from growing unbounded and ensure timely disposition decisions.