Delete folder

Prev Next

During remediation, you can delete the potential threat's selected folder or folders on the endpoint remotely using the full path of the folder.

The Delete Folder reaction is executed when a folder is opened in the terminal, the folder is deleted once the endpoint is rebooted.

The delete folder reaction is supported on Windows, Linux, and macOS endpoints.

  1. Log on to Trellix EDR.

  2. Select MenuReal-time Search.

  3. On the Search box, enter a search expression.

  4. Click the search icon to start collecting data from managed devices.

  5. Based on the search expression, the list of events, processes, or devices is displayed.

  6. From the list, select the affected event, process, or device, then select ActionMitigateDelete Folder.

    A new window appears and then you can enter details:

    • Full path — The folder's full path.

  7. Click Confirm to complete the Delete Folder action.

    A confirmation message displays as the action launched is completed successfully.

  8. On the Action History dashboard, Action Status displays the delete folder action as Completed.