During an investigation, you can kill or stop the potential threat's process remotely using its hash, PID, name, or path. Killing or stopping the process helps to contain and restrict damage on the endpoint.
Log on to Trellix EDR.
Select Menu → Real-time Search.
On the Search box, enter a search expression.
Click the search icon to start collecting data from managed devices.
Based on the search expression, the list of events, processes, or devices is displayed.
From the list, select the affected event, process, or device, then select Action → Contain → Kill Process.
You can select any one of these methods and enter the respective details to kill process:
Kill Process by PID — The process ID, set by the operating system.
Important
This reaction kills a process by its process ID and is supported on Windows, Linux, and macOS endpoints.
Kill Process by Hash — The process's hash value and the process ID.
Important
This reaction kills a process and its child processes (you need to select a checkbox to kill child processes) using its hash value. The reaction is supported on Windows and macOS endpoints.
Kill Process by Name — The name of the process.
Important
This reaction kills a process by its name and is supported on Windows, Linux, and macOS endpoints.
Kill Process by Path — The process's full path and the process ID.
Important
This reaction kills a process by its full file path and is supported on Windows, Linux, and macOS endpoints.
Kill Process Tree — The process ID, set by the operating system.
Important
This reaction kills a process and its child processes using its process ID and is supported on Windows and macOS endpoints.
Click Confirm to complete the Kill Process action.
A confirmation message displays as the action launched is completed successfully.
On the Action History dashboard, Action Status displays the kill process action as Completed.