After identifying a suspicious or malicious process running on an endpoint, you can terminate the process using context menus on the Trend Vision One console.
Trend Micro recommends blocking the suspicious process using the User-Defined Suspicious Objects List before sending the Terminate command to prevent endpoints from restarting the terminated process.
For more information, see Add to Block List Task.
The Terminate Task screen appears.
This task is only available for certain operating systems. You can only select endpoints running compatible operating systems.
Trend Vision One creates the task and displays the current command status on the Response Management app.
In progress... (): Trend Vision One sent the command
to the managing server and is waiting for a response
Queued (): The managing server queued the command
because the Security Agent was offline
Successful (): The managing server successfully received
the command
Unsuccessful (): An error or time-out
occurred when attempting to send the command to the managing server, the Security
Agent is offline for more than 24 hours, or the command execution timed out
The Task status indicates whether the managing server was able to successfully receive and execute the command. If the command target is a Security Agent, the Task status does not necessarily indicate whether the target Security Agent or object successfully executed the command.
To prevent endpoints from restarting terminated processes, block the object using the User-Defined Suspicious Objects List.
For more information, see Add to Block List Task.