Moorfox
A computer inside a dashed quarantine fence: the links to two neighbouring PCs stop at the fence, one line runs out to the control plane

How do I isolate a computer I think is infected?

· 2026-09-29 · 9 min read

Quick answer

Cut the machine off the network but leave it switched on. Either disable its switch port and Wi-Fi, which also cuts your RMM, or use Windows Firewall to block everything except your management agent and DNS: add the allow rules first, then netsh advfirewall set allprofiles firewallpolicy blockinboundalways,blockoutbound.

Then, from a different machine, disable the user in Active Directory, revoke their Entra sessions and reset the password. Check file servers for sessions from the machine's IP, export the event logs, and do not wipe, reimage or run a full scan until you know how it got in.

The call comes in one of a few ways: a ransom note on the screen, a remote tool the client never installed, a Defender alert, a payment the bank flagged. The machine is probably compromised. For the next hour, stop it reaching anything else while keeping it running and keeping your own way in; fixing it comes later.

This post is that hour: the commands, the order, and a checklist at the end to work down. The investigation that comes after is in How do I check if a Windows PC has been hacked?.

What does containing an infected computer mean?

Containment means the machine can no longer talk to the file server, the other PCs, the internet or whoever is controlling it. It keeps running, and you can still reach it.

It is not cleaning and it is not rebuilding. Those come later, once you know how the attacker got in, because a machine rebuilt without knowing that goes the same way again.

The order is contain, preserve, investigate, then clean or reimage. Swap any two and you either let it spread or destroy the evidence. Wipe first and the running processes and live connections that showed how it happened are gone. Investigate while it is still on the network and the ransomware keeps working on the share while you read logs.

What should I do in the first five minutes?

How do I cut it off the network without losing my own access?

The simplest containment is physical: pull the cable, or disable the port on the switch, and turn off Wi-Fi. Disabling the switch port beats disabling the adapter inside Windows, because whoever controls the machine can turn an adapter back on. The catch is that pulling the cable also cuts your RMM agent, so from then on everything you want to do on that machine needs someone standing at it.

The alternative is to isolate it with Windows Firewall: block everything, then allow only your management tool. Order matters here. Add the allow rules first and switch the default to block last, or the last command cuts the connection you typed it over.

netsh advfirewall set allprofiles state on
netsh advfirewall firewall add rule name="IR keep RMM" dir=out action=allow program="C:\Program Files\YourRMM\agent.exe"
netsh advfirewall firewall add rule name="IR keep DNS" dir=out action=allow protocol=UDP remoteport=53
netsh advfirewall set allprofiles firewallpolicy blockinboundalways,blockoutbound

Replace the program path with your own agent's executable. DNS needs a rule of its own because Windows resolves names in the DNS Client service inside svchost, not in your agent's process, so a program rule for the agent does not cover it. Rehearse the sequence on a lab machine before you need it: with a wrong path in the allow rule, the last command locks you out.

To undo it later:

netsh advfirewall set allprofiles firewallpolicy blockinbound,allowoutbound
netsh advfirewall firewall delete rule name="IR keep RMM"
netsh advfirewall firewall delete rule name="IR keep DNS"

Allow rules already on the machine keep working after the default flips to block. On a domain network that often means inbound File and Printer Sharing or Remote Desktop rules, and some applications install outbound allow rules of their own. That is why the command above uses blockinboundalways rather than blockinbound: it blocks inbound traffic even where an allow rule exists, while replies to connections the machine opened itself, your agent's included, still come back. Outbound has no equivalent switch, so list the rules that would still let traffic out and disable the ones you do not need:

Get-NetFirewallRule -Direction Outbound -Action Allow -Enabled True

Firewall isolation has two more limits. A local administrator on that machine, including an attacker who has admin, can undo the rules. And new rules block new connections; a connection that was already open when they went on can carry on. So once it is isolated, look at what is running and end suspicious processes and remote sessions, or restart the machine once you have captured what you need.

Finally, block the machine's IP address at the perimeter firewall, along with any unfamiliar remote addresses you saw in netstat -abno.

Should I shut the computer down?

Not by default. Memory holds evidence that a shutdown throws away: running processes, network connections, and sometimes the attacker's tools, which may only ever have existed in memory. A shutdown also hands whatever persistence the attacker set up a clean start on the next boot.

The exception is data being destroyed right now, for example ransomware visibly encrypting a file share. Then stopping the damage matters more than the evidence: pull the power rather than shutting down cleanly, and accept the loss.

If the disk is encrypted with BitLocker and the machine does go off, whoever images the disk later needs the recovery key. Find it now, not when the machine is on the bench.

Which accounts do I lock, and from where?

Assume the attacker has the credentials of whoever was signed in. Do all of this from a different, clean machine, never from the suspect one, because anything typed there may be captured.

How do I check whether it has already spread?

The machine talked to other things before you cut it off. Find out which.

What evidence should I keep before cleaning up?

Do not wipe, reimage or run a cleanup tool before you have looked. A full antivirus scan deletes exactly the files you need to see.

Tell the client's decision maker early, and their cyber insurer if they have cover. Insurers often have approved incident-response vendors and conditions about what you may do before those vendors arrive, and doing the wrong thing first can affect the claim. If the client has no written plan for any of this, the incident response plan template is one page.

The containment checklist

Copy this into the ticket and tick it off as you go.

Right now

Cut it off

Accounts, from a clean machine

Check the spread

Preserve

Tell people

How does Moorfox isolate a machine in one click?

Moorfox's network isolation does the same job as the firewall recipe above: block by default, keep the agent's own allow rules, and put those on before the block. On the device page, open Actions and choose Isolate network..., then type the device name back to confirm. That confirmation is the only extra step.

Isolation cuts the machine off the LAN and the internet by default and keeps the Moorfox agent connected, so remote desktop (falling back to the relay), the terminal, file explorer, processes, services and saved commands all still work on the contained machine. DNS and DHCP stay open by design, so the machine keeps its address and can still find Moorfox. On Windows it sets the firewall default to block in and out, and allow rules already on the machine still apply; the network isolation guide has the details.

Frequently asked questions

Should I unplug an infected computer or turn it off?

Unplug it from the network, but leave it on. Turning it off destroys what is in memory. The exception is data being actively destroyed, such as a share being encrypted right now.

Does disabling the network adapter in Windows isolate the machine?

Not reliably. Whoever controls the machine can turn it back on. Disable the switch port, or use firewall isolation that you control.

Can I still work on an isolated machine remotely?

Only if the isolation leaves your remote tool an allow rule. Pulling the cable cuts your access too; firewall isolation done in the right order keeps it.

Does isolating a machine stop an attacker who is already connected?

Not by itself. Firewall rules stop new connections; a session already open can carry on. End the suspicious processes and sessions, or restart after capturing what you need.

When can I reconnect it?

After you know how it was compromised, the entry point is closed, credentials are reset, and the machine is cleaned or, more often, reimaged.

Should I run a full antivirus scan straight away?

Not before you have captured evidence, because the scan removes the files you need to look at.