During remediation, you can stop a running process and remove its file remotely, only if the file is not critical or not trusted. If the process is not running, only its file is removed from the endpoint.
The stop and remove file safe reaction is supported on Windows and macOS endpoints.
Log on to Trellix EDR.
Select Menu → Real-time Search.
On the Search box, enter a search expression.
Click the search icon to start collecting data from managed devices.
Based on the search expression, the list of events, processes, or devices is displayed.
From the list, select the affected event, process, or device, then select Action → Mitigate → Stop and Remove FileSafe.
A new window appears and then you can enter details:
Full file path — The process's full path.
Hash value — The process's MD5, SHA-1, or SHA-256 hash value.
Click Confirm to complete the Stop and Remove File Safe action.
A confirmation message displays as the action launched is completed successfully.
On the Action History dashboard, Action Status displays the stop and remove file safe action as Completed.