> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security Operations Actions in Endpoint Detection

> Manage threat detection status, apply tags, and take response actions in Iru EDR. Streamline security operations workflows for incident management.

<Callout icon="list-check" color="#71118C" iconType="regular">This guide applies to Mac computers and Windows devices</Callout>

### About Security Operations Actions

Security Operations (SecOps) actions are the controls available in an endpoint security or EDR workflow that let administrators review detections and take follow-up steps such as updating status, investigating details, isolating compromised devices, or performing other response tasks in the Iru Endpoint Web App. In Iru Endpoint Detection & Response, these actions are surfaced on the Detections page and include updating the detection's Status to track progress through review and remediation.

### How It Works

Security Operations actions provide a structured approach to threat management through status tracking and tagging systems. The **Status** action on the Detections page in Endpoint Detection lets you track and update detection events as you work through them. As an admin, you can manually mark detections as **Open** or **Closed**, while Iru Endpoint automatically assigns other statuses based on timing, such as when the detection first occurred or how long it's been resolved. This creates a consistent workflow that helps you see what's new, what needs attention, and what's been handled, making it easier to triage threats and track progress across your fleet.

The **Status** column is available in the detections table for file detections on all platforms. On Mac computers, it is also available for behavioral detections.

### Understanding Detection Status Types

Detection events can have one of four statuses:

* **New**: Occurred within the last 24 hours
* **Open**: Not yet marked as closed
* **Closed**: Resolved by manually marking as Closed
* **Archived**: Closed for more than 30 days

**Automatic management**: The **New** and **Archived** statuses are set automatically by Iru Endpoint. You can manually change a detection between **Open** and **Closed**.

### Filtering Detection Events by Status

You can filter detection events by status on the **Detections** page:

* **Event filter**: By default, shows **New**, **Open**, and **Closed** events. **Archived** events are hidden unless selected.
* **Device filter**: Located in the side panel, allows filtering devices by **Open** or **Closed** detections.

### Changing Detection Status

<Note>
  Updating statuses regularly helps keep detection lists accurate and improves filtering for active threats.
</Note>

<Steps>
  <Step title="Select Detections">
    Select the detection(s) using the checkbox.
  </Step>

  <Step title="Access Status Change">
    Click **Change Status** in the action bar.
  </Step>

  <Step title="Choose New Status">
    Choose the new status from the dropdown menu.
  </Step>

  <Step title="Apply Changes">
    Click **Change** to apply.
  </Step>
</Steps>

You can update detections individually or in bulk.

### Platform-Specific Response Actions

<Tabs>
  <Tab title="macOS" icon="apple" iconType="brands">
    ### Device Isolation

    Device Isolation is a critical security operations capability that allows administrators to immediately quarantine a device from the network when it's suspected of being compromised or under active threat. The detections side panel provides access to [device isolation](/en/endpoint/endpoint-detection-response-edr/device-isolation) for Mac computers.

    Device Isolation provides two isolation levels:

    * **Partial Isolation**: Disconnects the device from the network while maintaining MDM agent connectivity for remote remediation actions
    * **Complete Isolation**: Completely cuts off all network communication, with release from isolation being the only available remote action

    Device Isolation can be performed on individual devices or in bulk across all devices affected by a specific threat detection. Isolation and release actions are recorded on the [Unified Activity](/en/iru/platform-overview/unified-activity). For detailed instructions on isolating and releasing devices, see the [Device Isolation](/en/endpoint/endpoint-detection-response-edr/device-isolation) article.
  </Tab>

  <Tab title="Windows" icon="microsoft" iconType="brands">
    Status updates and tag management above apply to Windows file detections. Use **Change Status** and **Assign tags** to track and organize malware and PUP detections on enrolled Windows devices.
  </Tab>
</Tabs>

### About Detection Organization Tags

Tags provide a flexible way to organize, filter, and manage threats based on your team's specific operational needs. These admin-defined tags streamline threat management and enhance collaboration by allowing you to categorize detections with custom labels that align with your workflow.

The Detections page includes a Tags column, giving you visibility into which tags are associated with each threat. If a threat has multiple tags, you can hover over the column to see the full list.

### Managing Tags

#### Creating Tags

You have full control over your tags. To create, modify, or delete tags, click the **Manage Tags** button. This allows you to customize and maintain a tagging system that aligns with your team's operational needs.

<Steps>
  <Step title="Access Tag Management">
    Select the **Manage Tags** icon in the upper right-hand corner of the Detections page.
  </Step>

  <Step title="Add New Tag">
    Click **Add Tag**.
  </Step>

  <Step title="Enter Tag Text">
    Enter your desired **tag text**. Select the **checkmark** to save, and repeat as desired for the number of tags you want to add.
  </Step>

  <Step title="Close Modal">
    **Close** the modal.

    <Frame>
      <img src="https://mintcdn.com/iru/zSGoLeQBJVMEeX1b/assets/media/images/Kandji-Support-KB-0239PM@2x.png?fit=max&auto=format&n=zSGoLeQBJVMEeX1b&q=85&s=fa49456c05319438b5fb01d213d32e8d" alt="Security Operations modal or action interface with Close" width="990" height="880" data-path="assets/media/images/Kandji-Support-KB-0239PM@2x.png" />
    </Frame>
  </Step>
</Steps>

#### Updating Tags

<Steps>
  <Step title="Access Tag Management">
    Select the **Manage Tags** icon in the upper right-hand corner of the Detections page.
  </Step>

  <Step title="Edit Tag">
    Click the **pencil icon** next to the tag you want to edit.
  </Step>

  <Step title="Update Tag Text">
    Update the **tag text**, then click the **check**.
  </Step>

  <Step title="Close Modal">
    **Close** the modal.
  </Step>
</Steps>

#### Deleting Tags

<Steps>
  <Step title="Access Tag Management">
    Select the **Manage Tags** icon in the upper right-hand corner of the Detections page.
  </Step>

  <Step title="Delete Tag">
    Select the **Trash** icon to the right of the threat.
  </Step>

  <Step title="Close Modal">
    **Close** the modal.
  </Step>
</Steps>

#### Assigning Tags to Detections

<Steps>
  <Step title="Select detections">
    Select one or more **detections** from the list.
  </Step>

  <Step title="Access Actions Menu">
    Click on the **ellipsis** in the lower left corner.
  </Step>

  <Step title="Assign Tags">
    Select **Assign tags**, and select your tags from the list.

    <Frame>
      <img src="https://mintcdn.com/iru/zSGoLeQBJVMEeX1b/assets/media/images/Kandji-Support-KB-0406PM@2x.png?fit=max&auto=format&n=zSGoLeQBJVMEeX1b&q=85&s=a4180debaae55775a8f26941888da855" alt="Assign tags option and tag list for threat detection" width="2448" height="956" data-path="assets/media/images/Kandji-Support-KB-0406PM@2x.png" />
    </Frame>
  </Step>
</Steps>

### Filtering Detections by Tags

You can filter the detections table by selecting one or more tags from the top filter. This helps you focus on specific types of threats or tasks.

### Considerations

* **Status Management**: Regularly update detection statuses to maintain accurate threat tracking and improve filtering effectiveness
* **Tag Strategy**: Develop a consistent tagging strategy that aligns with your team's operational workflows and threat classification needs
* **Bulk Operations**: Use bulk status changes and tag assignments to efficiently manage multiple detections simultaneously
* **Filter Combinations**: Combine status and tag filters to create focused views for specific threat types or operational priorities
* **Team Collaboration**: Establish clear guidelines for status updates and tag usage to ensure consistent threat management across your security team
* **Automated Statuses**: Understand that **New** and **Archived** statuses are automatically managed by Iru Endpoint based on timing, while **Open** and **Closed** require manual intervention
* **Threat Prioritization**: Use status and tag combinations to prioritize threats that require immediate attention versus those that can be addressed later
