During remediation, you can remove a file from the endpoint remotely by its full name even if the file is trusted or critical.
If a specific file can't be deleted because of a process blocking it, the file is deleted when the endpoint reboots.
The remove file reaction is supported on Windows, Linux, and macOS endpoints.
Log on to Trellix EDR.
Select Menu → Real-time Search.
On the Search box, enter a search expression.
Click the search icon to start collecting data from managed devices.
Based on the search expression, the list of events, processes, or devices is displayed.
From the list, select the affected event, process, or device, then select Action → Mitigate → Remove File.
A new window appears and then you can enter details:
Full file path — The process's full path.
Click Confirm to complete the Remove File action.
A confirmation message displays as the action launched is completed successfully.
On the Action History dashboard, Action Status displays the remove file action as Completed.