Using Assisted Remediation

Assisted Remediation automates the execution of customized remediation actions provided by Huntress. Upon approval, the Huntress Agent will perform the remediation actions on your behalf. Before Assisted Remediation, an IT support technician would manually perform the Remediation. Manual Remediation requires connecting to the host via a remote support utility and carrying out Huntress's remediation instructions. In some cases, it also required coordinating with the end-user. Now, on eligible steps in an incident, a button will appear in the Huntress Portal, allowing technicians to approve and automate the commands required to remediate.

If an incident is reported where assisted Remediation is available, a button labeled "Review Remediation Plan" will be visible in the Huntress Portal. Please note, there are cases were manual Remediation may be required.

After reviewing the remediation plan, the technician can choose to either approve or reject the listed steps for Remediation:

If for some reason, you don't approve of the remediation plan, it can be rejected. As part of the rejection process, you can provide details about why it isn't approved. This allows Huntress to conduct further investigation and make the suggested corrections and re-issue the incident report:

Manual Remediation

Certain incidents cannot be handled through Assisted Remediation. These incidents will display a red "x" on the "Review Remediation Plan" button and must be remediated by performing the tasks described in the incident report. Some cases where manual intervention is required:

  • Malware that has modified system files and removing those files may leave the system unusable
  • Malware that has modified an existing registry value rather than creating a new value

NOTE: There are cases where the Remediation may fail, most often due to the file being in use. The agent will attempt to stop services and scheduled tasks, but it does not explicitly terminate processes. If the process is running, it may prevent the associated file from being removed; in these cases, manual Remediation is required.

Still need help? Contact Us Contact Us