Views:

After identifying a suspicious or malicious process running on an endpoint, you can terminate the process using context menus on the Trend Vision One console.

This task is supported by the following services:
  • Apex One as a Service
    • Windows agent
Important
Important
Trend Micro recommends blocking the suspicious process using the User-Defined Suspicious Objects List before sending the Terminate command to prevent endpoints from restarting the terminated process.
For more information, see Add to Block List task.

Procedure

  1. After identifying the suspicious process, access the context or response menu and click Terminate.
    The Terminate Task screen appears.
  2. Confirm the targets of the response.
    Important
    Important
    This task is only available for certain operating systems. You can only select endpoints running compatible operating systems.
  3. Specify a Description for the response or event.
  4. Click Create.
    Trend Vision One creates the task and displays the current task status in Response Management.
  5. Monitor the task status.
    1. Open Response Management.
    2. (Optional) Locate the task using the Search field or by selecting Terminate from the Action drop-down list.
    3. View the task status.
      • In progress (in-progress.jpg): Trend Vision One sent the command and is waiting for a response.
      • Queued (queued.jpg): The managing server queued the command because the agent was offline.
      • Successful (successful_001.jpg): The command was successfully executed.
      • Unsuccessful (error.jpg): An error or time-out occurred when attempting to send the command to the managing server, the agent is offline for more than 24 hours, or the command execution timed out.
      Important
      Important
      • The Task status indicates whether the managing server was able to successfully receive and execute the command. If the command target is a Security Agent, the Task status does not necessarily indicate whether the target Security Agent or object successfully executed the command.
      • To prevent endpoints from restarting terminated processes, block the object using the User-Defined Suspicious Objects List.
        For more information, see Add to Block List task.