Skip to content

Commit 95ad2dd

Browse files
Merge pull request #3093 from MicrosoftDocs/gary-restage-public-pr-ayush
Restaged PR: Adding remediate infected file optional feature doc
2 parents d047759 + 1cd1ecd commit 95ad2dd

File tree

1 file changed

+17
-2
lines changed

1 file changed

+17
-2
lines changed

defender-endpoint/linux-preferences.md

Lines changed: 17 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.service: defender-endpoint
66
ms.author: deniseb
77
author: denisebmsft
88
ms.localizationpriority: medium
9-
ms.date: 03/05/2025
9+
ms.date: 03/11/2025
1010
manager: deniseb
1111
audience: ITPro
1212
ms.collection:
@@ -662,6 +662,20 @@ Determines whether module load events (file open events on shared libraries) are
662662
|**Possible values**|disabled (default) <p> enabled|*n/a*|
663663
|**Comments**|Available in Defender for Endpoint version `101.68.80` or later.||
664664

665+
#### Remediate Infected File feature
666+
667+
Determines whether infected processes that open or load any infected file will get remediated or not.
668+
669+
> [!NOTE]
670+
> When enabled the processes that open or load any infected file will be remediated in RTP mode. These processes will not appear in the threat list as these are not malicious but are only being terminated because they were loading the threat file in memory.
671+
672+
|Description|JSON Value|Defender Portal Value|
673+
|---|---|---|
674+
|**Key**|remediateInfectedFile|*Not available*|
675+
|**Data type**|String|*n/a*|
676+
|**Possible values**|disabled (default) <p> enabled|*n/a*|
677+
|**Comments**|Available in Defender for Endpoint version `101.24122.0001` or later.||
678+
665679
#### Supplementary sensor configurations
666680

667681
The following settings can be used to configure certain advanced supplementary sensor features.
@@ -963,7 +977,8 @@ The following configuration profile contains entries for all settings described
963977
"sendLowfiEvents":"disabled"
964978
},
965979
"ebpfSupplementaryEventProvider":"enabled",
966-
"offlineDefinitionUpdateVerifySig": "disabled"
980+
"offlineDefinitionUpdateVerifySig": "disabled",
981+
"remediateInfectedFile": "enabled"
967982
},
968983
"networkProtection":{
969984
"enforcementLevel":"disabled",

0 commit comments

Comments
 (0)