Stop and remove content

Prev Next

During remediation, you can stop the interpreter processes such as Python and Bash by the process ID and remove the associated script remotely using the full path.

The Stop and Remove Content reaction is supported on Windows and macOS endpoints.

  1. Log on to Trellix EDR.

  2. Select MenuReal-time Search.

  3. On the Search box, enter a search expression.

  4. Click the search icon to start collecting data from managed devices.

  5. Based on the search expression, the list of events, processes, or devices is displayed.

  6. From the list, select the affected event, process, or device, then select ActionMitigateStop and Remove Content.

    A new window appears and then you can enter details:

    • Process ID — The process ID.

    • Full file path — The process's full path.

  7. Click Confirm to complete the Stop and Remove Content action.

    A confirmation message displays as the action launched is completed successfully.

  8. On the Action History dashboard, Action Status displays the stop and remove content action as Completed.