Issue ID: EDR-06
Applies to: Datto EDR, Datto AV
Environment: Windows, macOS
KB type: Troubleshooting
Purpose
Use this article when a file has been deleted or quarantined by Datto EDR or Datto AV without a clear alert or log entry visible to the customer, and you need to confirm what happened and prevent recurrence.
Symptoms
- A file expected to be present is missing, with no alert shown for it.
- No record is found explaining why or when the file was removed.
- A business-critical application file is affected, causing operational impact.
Cause
Files are typically removed by automated detection or remediation actions (quarantine, ransomware rollback, deletion) rather than manual user actions.
- For Datto EDR and AV, file removals (quarantine or deletion) are triggered by detection rules or policies.
- Not all removals generate visible alerts if alert-only mode is enabled in Datto AV.
- For Ransomware Rollback, audit history is not available in the EDR portal; it is stored locally on the device.
Troubleshooting Steps
1. Gather Details
- Record the exact file path, file name, and the endpoint where the file was removed.
- Record the approximate date and time the file went missing, if known.
2. Check for Quarantine or Removal Records
Datto EDR/AV:
- In the Datto EDR portal, navigate to Respond > Quarantined Files to review the quarantine and remediation history for the affected endpoint.
- Quarantined files are listed here, along with the detection rule or policy that triggered the action. Refer to Managing quarantined files
- If the file is not listed under Quarantined Files, check the Respond tab for any removal or deletion reports. Refer to Responding to alerts
Ransomware Rollback:
- Ransomware Rollback does not maintain an audit history in the Datto EDR portal. Instead, audit logs are stored locally on the endpoint and can be accessed through the Datto Rollback interface.
- If Ransomware Rollback is suspected, access the affected endpoint and review the local rollback logs.
3. Restore Files If Removed In Error
Datto EDR/AV:
- If a file was quarantined in error or is business-critical, restore it from Respond > Quarantined Files in the Datto EDR portal. Refer to How to address false positives.
Ransomware Rollback:
- If restoration is required for a rollback event, use the Datto Rollback interface on the local device. Refer to Working with Ransomware Rollback.
4. Prevent Recurrence With Exclusions
To add exclusions for Datto AV:
-
Add an exclusion for the affected file, folder, or process to the Datto AV policy to prevent future removals.
Exclusions can be added through the policy configuration page in your Datto EDR portal. Refer to Working with exclusions in your Datto AV policy
To add exclusions for Ransomware Rollback:
-
Open RegEdit on the endpoint and navigate to:
Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Datto\RollbackDriver - Create a registry key named Debug and set its value to 1.
- Open the Rollback Desktop application.
- Click the Settings (gear) icon to open Rollback Configuration.
- Add the required exclusions.
5. If Unresolved, Contact Kaseya Support
- Document the business impact, including the affected application, downtime, and any data loss. If the file cannot be located or restored, escalate the case with the file details and the documented business impact.
Tips and Tricks
- Verify the file has not been removed by the operating system. Check standard OS locations, such as the Recycle Bin on Windows or
.Trashon macOS.
Related Articles
- Managing quarantined files
- How to address false positives.
- Working with exclusions in your Datto AV policy
- Navigating the Respond page