Analysis & Remediation - Termination of Trusted Processes (LOLbins)
Recommendation
Enable termination of trusted processes as part of automatic attack remediation.
Configuration Path
Policy > Threat Prevention > Policy Capabilities > Analysis & Remediation > Advanced Settings > File Remediation > Trusted Files = Terminate
Description
Trusted processes include signed operating system binaries commonly present on endpoints. Attackers can abuse these processes as part of the attack chain. These processes are commonly referred to as living-off-the-land binaries (LOLbins), for example, powershell.exe, svchost.exe, and certutil.exe.
Terminating trusted processes during remediation helps sanitize the complete attack chain. This stops detected attacks effectively and prevents continued malicious activity using trusted operating system components.
When enabled, fully remediated attacks reach a Cleaned status instead of remaining Active, reducing the risk of ongoing impact.
Operational Guidance
-
This setting is enabled by default in newly created Endpoint Security cloud tenants.
-
Existing cloud and on-premises environments must be reviewed.
-
Configure this setting explicitly in each applicable rule.