For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XDR 3.x

Remediate changes from malicious activity

You can obtain action remediation suggestions from Cortex XDR about malicious causality chains that have been detected.

Notice

This functionality requires a Cortex XDR Pro license.

When investigating suspicious incidents and causality chains you might need to restore and revert changes made to your endpoints as result of a malicious activity. To avoid manually searching for the affected files and registry keys on your endpoints, you can request remediation suggestions.

Prerequisite

How to initiate remediation suggestions

  1. You can initiate a remediation suggestions analysis from the following places:

    • In the Incidents view, click the more options icon in the incident panel and select Remediation Suggestions.

      Note

      Endpoints that are part of the Incident view and do not meet the required criteria are excluded from the remediation analysis.

    • In the Causality View:

      • Right-click any process node involved in the causality chain and select Remediation Suggestion.

      • Select Actions → Remediation Suggestions.

    Analysis can take a few minutes. You can minimize the analysis pop-up if desired while navigating to other pages.

  2. Review the remediation suggestion summary and details.

Field descriptions
Field
Description

Original Event Description

Summary of the initial event that triggered the malicious causality chain.

Original Event Timestamp

Timestamp of the initial event that triggered the malicious causality chain.

Endpoint Name

Hostname of the endpoint.

IP Address

IP address associated with the endpoint.

Endpoint Status

Connectivity status of the endpoint.

Domain

Domain or workgroup to which the endpoint belongs, if applicable.

Endpoint ID

Unique ID assigned by Cortex XDR that identifies the endpoint.

Suggested Remediation

Action suggested by the remediation scan for you to apply to the causality chain process:

  • Delete File.

  • Restore File.

  • Rename File.

  • Delete Registry Value.

  • Restore Registry Value.

  • Terminate Process

    Available when selecting Remediation Suggestions for a node in the Causality View.

  • Terminate Causality

    Terminate the entire causality chain of processes that have been executed under the process tree of the listed Causality Group Owner (GCO) process name.

  • Manual Remediation

    Requires you to take manual action to revert or restore.

Suggested Remediation Description

Summary of the remediation suggestion to apply to the file or registry.

Remediation Status

Status of the applied remediation.

Remediation Date

Displays the timestamp of when all of the endpoint artifacts were remediated. If missing a successful remediation, the field will not display the timestamp.

  1. Select one or more rows, right-click and select Remediate.

  2. Track your remediation process.

    Go to Response → Action Center → All Actions and locate your remediation process in the Action Type field. Right-click Additional data to open the Detailed Results window.

Last updated

Was this helpful?