During an investigation, you can stop the potential threat's process remotely to contain and restrict damage on the endpoint. It stops associated parent to child processes using its hash value.
The Stop process feature uses the Kill Process By Hash reaction functionality to stop the process.
The Stop process feature is supported on Windows and macOS endpoints.
Log on to Trellix EDR.
Select Menu → Monitoring.
On the Threats by Ranking / Threats by Time pane, select a threat to view the affected devices.
On the Device pane, select one or more affected devices to enable the Device Actions drop-down list.
From the Device Actions menu, select Stop Process.
Click Confirm to complete the containment process.
You can check the action status to confirm that the stop process action is completed:
On the Monitoring dashboard, refresh the device list.
On the Action History dashboard, Action Status displays the stop process action as Completed.