Quarantine endpoint

A GET request to /api/open/quarantine allows you to get a file from the quarantine directory.

Requirements and Restrictions

  1. The authenticated user must be in a group having admin role.
  2. The full path of the file must be specified in the file parameter and the format should be /data/quarantine/<NAME>.
  3. If you specify a path that does not exist, the call returns a 404 error.
  4. If the request is accepted, the result will contain the actual file that Guardian extracted from traffic and that the Sandbox classified as malicious.
Figure 1. Example of request

Example of request

Hint: as shown in the top part of the previous screenshot, the file parameter to be used with the request can be found in the properties field of SIGN:MALWARE-DETECTED alerts.