Use Case

Isolate a compromised host from your phone — with biometric confirmation.

Host containment is the act of network-isolating a compromised endpoint so it cannot continue to spread, exfiltrate, or beacon out. PocketSOC enables host containment from a mobile device using vendor-native isolation APIs (CrowdStrike RTR network containment, Microsoft Defender for Endpoint machine isolation). Every containment action requires biometric authentication plus explicit confirmation — there is no swipe-to-isolate by accident.

The problem

A real intrusion is in progress on a developer laptop. The host is beaconing out, the EDR is screaming, and the responder is on a bus. Containment cannot wait for the responder to get to a desk — every minute the host stays online is more lateral movement, more credential theft, more exfiltration. But containment is a high-impact action that needs a confirmation step strong enough to survive a misplaced thumb.

The PocketSOC workflow

  1. Open the detection in PocketSOC and confirm the affected host is genuinely compromised
  2. Tap "Isolate Host"
  3. Authenticate with Face ID, Touch ID, or device passcode
  4. Read the explicit confirmation prompt (host name, vendor, action) and confirm
  5. PocketSOC issues the vendor isolation API call and confirms success
  6. Notify your team — the action is logged in the vendor audit trail and in PocketSOC
  7. Once the investigation closes, repeat the flow to lift isolation

Outcomes

Supported vendors for this workflow