When the investigation is completed and identified a threat as potentially malicious, you can remove a threat remotely or delete artifacts such as process, folder, file, registry value, or content permanently from the endpoint.
During remediation or eradication, EDRF identifies all affected endpoints within the environment so that threats from the affected endpoints are remediated.
If the target endpoints are offline when the remediation or mitigation reaction is executed, the response reaction is saved and executed when the endpoint is back online.
Important
Run the HostInfo query on Real-time Search to list endpoints and their connectivity status (online or offline).
When you execute a reaction and select all displayed results to take action, the action is executed on all impacted endpoints present in your environment. This includes endpoints not responded to the search query due to endpoint shutdown, connectivity issue, etc.
Note
You can now initiate remediation action for the affected endpoints. These actions are processed in a batch of 1500 without user intervention and the status of these actions can be viewed under Action History UI dashboard.
You can use the following reactions to remediate threats remotely:
You can also create and execute custom reactions to respond to threats.