For the complete documentation index, see llms.txt. This page is also available as Markdown.

Remediate changes from malicious activity

Remediate changes caused by malicious activity.

When investigating cases and causality chains you might need to restore and revert changes made to your endpoints as result of a malicious activity. To avoid manually searching for the affected files and registry keys on your endpoints, you can request remediation suggestions.

Prerequisite

How to initiate remediation suggestions

  1. You can initiate a remediation suggestions analysis from the following places:

    • In the Cases view, click the more options icon in the cases panel and select Remediation Suggestions.

      Note

      Endpoints that are part of the Case view and do not meet the required criteria are excluded from the remediation analysis.

    • In the Causality View:

      • Right-click any process node involved in the causality chain and select Remediation Suggestion.

      • Select Actions → Remediation Suggestions.

    Analysis can take a few minutes. You can minimize the analysis pop-up if desired while navigating to other pages.

  2. Review the remediation suggestion summary and details.

Field descriptions
  1. Select one or more rows, right-click and select Remediate.

  2. Track your remediation process.

    Go to Investigation & Response+Response → Action Center → All Actions and locate your remediation process in the Action Type field. Right-click Additional data to open the Detailed Results window.

  1. Select one or more rows, right-click and select Remediate.

  2. Track your remediation process.

    Go to Investigation & Response+Response → Action Center → All Actions and locate your remediation process in the Action Type field. Right-click Additional data to open the Detailed Results window.

Last updated

Was this helpful?