EDR Release 3.8.5
September 18, 2026
Add to Blocklist Directly from a Hunting Event
You can now add a SHA256, Appname, URL, or IP to the blocklist of your EDR profiles directly from an event on the Hunting page, so you can block a threat as soon as you find it, without leaving your investigation. Previously, you could add blocklist entries only from the blocking configuration of a profile, where you had to type in the value to block and repeat the task for each profile you wanted to protect.
The Add to BlockList is supported for events from Windows and macOS assets only. Linux assets are not supported.
The Add to BlockList option is available from the Quick Actions menu of an event on the Events tab of the Hunting page. The Items to Be Blocked section of the Add To Blocklist window shows the Type of item to block (such as SHA256, Appname, URL, or IP) and the Object, which is the value taken from the event, so there is nothing for you to enter or copy.

For events from the macOS platform, Add to BlockList supports only the Appname and URL types. The SHA256 and IP types are not supported.
From the Add To Blocklist window, you can also:
- Apply the block to one or more EDR profiles, or to all your profiles, in a single action. Only profiles with the corresponding blocking configuration enabled are listed.
- Schedule when an Appname is blocked, at all times, or only on the days and hours you choose.

The entries that you add from the Hunting page are displayed in the blocking configuration of the selected profiles, where you can review or remove them as before.
For more information, refer to EDR Online Help.