During remediation, you can delete the Windows registry value remotely in a specified registry key path.
Important
This reaction can only delete key values that are not protected by other software.
The Delete Registry Value reaction is supported only on Windows endpoints.
Log on to Trellix EDR.
Select Menu → Real-time Search.
On the Search box, enter a search expression.
Click the search icon to start collecting data from managed devices.
Based on the search expression, the list of events, processes, or devices is displayed.
From the list, select the affected event, process, or device, then select Action → Mitigate → Delete Registry Value.
A new window appears and then you can enter details:
Key path — The absolute path to a registry key. The path does not include the key value name.
Key value — The key value name to erase.
Click Confirm to complete the Delete Registry Value action.
A confirmation message displays as the action launched is completed successfully.
On the Action History dashboard, Action Status displays the delete registry value action as Completed.