Skip to content

Maintenance Mode

Maintenance Mode prevents the XDR Forensics Console from generating or assigning tasks to an asset. When activated, the Console will not allow you to create tasks for that asset—this includes manual task creation, scheduled tasks, and bulk task assignments.

When you place an asset into Maintenance Mode:

  1. Task creation is blocked — You cannot generate new tasks for the asset from the Console
  2. Scheduled tasks are skipped — Any scheduled tasks that would target this asset will not execute
  3. Bulk tasks exclude the asset — The asset is automatically excluded from bulk task operations
  4. In-progress tasks continue — Tasks that were already executing when Maintenance Mode was activated will run to completion

To support essential diagnostic and investigative activities, the following actions are still permitted:

ActionStatusReason
interACT✅ AvailableEssential for live diagnostics
Log Gathering✅ AvailableRequired for troubleshooting
New Task Creation❌ BlockedPrimary function of Maintenance Mode
Scheduled Tasks❌ BlockedPrevented by Console
Bulk Tasks❌ BlockedAsset is excluded

Maintenance Mode can be enabled from the More Actions menu on any asset.

Maintenance Mode: Enabling via the More Actions button

When an asset is in Maintenance Mode, this status is clearly visible:

  • Asset Details Page: The Maintenance Mode status is displayed in the asset information panel
  • Asset Filters: Filter by Maintenance Mode status to identify maintained assets across large environments

Maintenance Mode: Status displayed on the Asset Info page

During system updates, patches, or configuration changes, activate Maintenance Mode to ensure no tasks—manual or automated—can be created for the asset until maintenance is complete.

When troubleshooting an asset, Maintenance Mode prevents accidental task execution while you investigate. interACT and log gathering remain available for diagnostics.

When working with cloned or duplicated asset instances, Maintenance Mode prevents conflicting task assignments. This helps analysts maintain chain-of-custody and ensures collected information remains contextually accurate.

Both features control asset behaviour, but serve different purposes:

FeatureMaintenance ModeAsset Isolation
Primary PurposePrevent task creationNetwork containment
Network AccessNormalTerminated
Task Creation❌ Blocked✅ Allowed
Scheduled Tasks❌ Blocked✅ Execute normally
interACT✅ Available✅ Available
Acquisition❌ Blocked✅ Available
Hunt/Triage❌ Blocked✅ Available