Skip to content

Commit ea776ae

Browse files
AyushSingh-cgarycentric
authored andcommitted
Update linux-preferences.md
Adding remediate infected file optional feature doc
1 parent 8765e4e commit ea776ae

File tree

1 file changed

+16
-1
lines changed

1 file changed

+16
-1
lines changed

defender-endpoint/linux-preferences.md

Lines changed: 16 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -660,6 +660,20 @@ Determines whether module load events (file open events on shared libraries) are
660660
|**Possible values**|disabled (default) <p> enabled|*n/a*|
661661
|**Comments**|Available in Defender for Endpoint version `101.68.80` or later.||
662662

663+
#### Remediate Infected File feature
664+
665+
Determines whether infected processes that open or load any infected file will get remediated or not.
666+
667+
> [!NOTE]
668+
> When enabled the processes that open or load any infected file will get remediated but these processes will not appear in the threat list.
669+
670+
|Description|JSON Value|Defender Portal Value|
671+
|---|---|---|
672+
|**Key**|remediateInfectedFile|*Not available*|
673+
|**Data type**|String|*n/a*|
674+
|**Possible values**|disabled (default) <p> enabled|*n/a*|
675+
|**Comments**|Available in Defender for Endpoint version `101.24122.0001` or later.||
676+
663677
#### Supplementary sensor configurations
664678

665679
The following settings can be used to configure certain advanced supplementary sensor features.
@@ -961,7 +975,8 @@ The following configuration profile contains entries for all settings described
961975
"sendLowfiEvents":"disabled"
962976
},
963977
"ebpfSupplementaryEventProvider":"enabled",
964-
"offlineDefinitionUpdateVerifySig": "disabled"
978+
"offlineDefinitionUpdateVerifySig": "disabled",
979+
"remediateInfectedFile": "enabled"
965980
},
966981
"networkProtection":{
967982
"enforcementLevel":"disabled",

0 commit comments

Comments
 (0)