Remediate changes from malicious activity
You can obtain action remediation suggestions from Cortex XDR about malicious causality chains that have been detected.
When investigating suspicious incidents and causality chains you might need to restore and revert changes made to your endpoints as result of a malicious activity. To avoid manually searching for the affected files and registry keys on your endpoints, you can request remediation suggestions.
Prerequisite
To initiate remediation suggestions, you must have the following system requirements:
Cortex XDR Pro per Endpoint license.
An App Administrator, Privileged Responder, or Privileged Security Admin role permissions which include the remediation permissions.
EDR data collection enabled.
Agent version 7.2 or above on Windows endpoints.
How to initiate remediation suggestions
You can initiate a remediation suggestions analysis from the following places:
In the Causality View:
Right-click any process node involved in the causality chain and select Remediation Suggestion.
Select Actions → Remediation Suggestions.
Analysis can take a few minutes. You can minimize the analysis pop-up if desired while navigating to other pages.
Review the remediation suggestion summary and details.
Select one or more rows, right-click and select Remediate.
Track your remediation process.
Go to Response → Action Center → All Actions and locate your remediation process in the Action Type field. Right-click Additional data to open the Detailed Results window.
Last updated
Was this helpful?
