Explore Expel’s auto remediations: Delete malicious file
ID: 98df4e99-ba56-597f-ab4f-5e59efd8dcb7
STIX ID: report--98df4e99-ba56-597f-ab4f-5e59efd8dcb7
Feed Name: Expel Blog
Threat Score
**Delete Malicious File Auto-Remediation:** This guidance explains Expel's process for identifying and deleting malicious files on endpoints as part of eradication after containment, using a banking trojan example (CredHarvest.exe) that dropped a DLL and a Base64-encoded config; it covers detection, analyst validation, customer approval, EDR-executed deletion, and confirmation/audit steps to prevent re-infection and support forensic follow-up.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
