Recover file from quarantine

Hi @GKre,

I'm sorry you've run in to this. We've actually identified this as a "bug" because its confusing to users and are trying to identify the best way to fix this.

A rule exception runs in Kibana and generally doesn't impact behavior on the Endpoint. In order to get your file released from quarantine (and prevent it from being quarantined again), you need to add an Endpoint Exception (which is about half way down the documentation page for exceptions). Add and manage exceptions | Elastic Security Solution [8.11] | Elastic

Adding an Endpoint exception will end up sending an update to your Endpoint in a few minutes which will release the file from quarantine and prevent it from being quarantined again.

Let me know if you run in to any issues getting it released.