> For the complete documentation index, see [llms.txt](https://docs.expel.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.expel.io/workbench-setup/auto-remediations/about-auto-remediations.md).

# About Auto Remediations

*If you are ready to set up your auto remediations, go to* [*Enable an Auto Remediation in Workbench*](/workbench-setup/auto-remediations/enable-an-auto-remediation-in-workbench.md)*.*

When you enable an auto remediation, you allow Expel to automate certain response capabilities within your system(s) so that attacks can be rapidly contained without requiring any intervention from you. All remediation actions are created in Workbench, but the actions themselves are taken within your specific vendor technologies.

* Our SOC analysts make the call on when and what to remediate based on the settings you specify.
* Expel automates the remediation action itself but not the decision to remediate.
* The remediation action is only initiated from an [Incident](/workbench-reference/expel-terminology.md#incident) and not from an [Investigation](/workbench-reference/expel-terminology.md#investigation) (exception: the attack surface is different for Managed Phishing, so we do initiate the remediation action from both).
* You have the option to customize a deny list so that certain files or paths are not subject to the actions of a remediation.
* You may disable a remediation at any time via Workbench.
* If for some reason Expel cannot complete the remediation, the action will be assigned to you to complete.

Auto remediations are configured by going to **Organization Settings** > **My Organizations** > **Auto Remediations** tab. You must have **Administrator** access in Workbench to configure auto remediations.

Watch our Introduction to Auto Remediations video to learn more.

{% embed url="<https://player.vimeo.com/video/1134411904?amp;app_id=58479&autopause=0&badge=0&byline=0&player_id=0&portrait=0&title=0&h=c4c1fcfb35>" %}

## **Available Auto Remediations** <a href="#h_01hz5c2axyn535hfes2n7e3mt3" id="h_01hz5c2axyn535hfes2n7e3mt3"></a>

Expel offers a number of auto remediations, which are enabled or disabled at the organization level. Use these links to skip ahead to learn more about the ones you are most interested in.

* [Block Known Bad Hashes](#h_01hz5c2axy8yyxhrqt99qr8vhx)
* [Contain Hosts](#h_01hz5c2axyj8rgnvfavbys88g9)
* [Deactivate Access Keys](#h_01hz5c2axynj0m4sb6wfgaz8xr)
* [Delete Malicious Files](#h_01hz5c2axyay1nxkt3mabxm921)
* [Delete Registry Key](#h_01hz5c2axz455wcshc3qm7v9d2)
* [Disable Accounts](#h_01hz5c2axz455wcshc3qm7v9d2)
* [Kill Processes](#h_01hz5c2axzbe8snapcbds4rypv)
* [Remove Malicious Email](#h_01hz5c2axztcyb5tz99gved5mm)
* [Reset Credentials](#id-01j7m2h11k0zab3fp6gfs2418c)

### **Block Known Bad Hashes** <a href="#h_01hz5c2axy8yyxhrqt99qr8vhx" id="h_01hz5c2axy8yyxhrqt99qr8vhx"></a>

Blocking known bad hashes (which may be referred to by different vendor technologies as application blocking, banning hashes, blacklisting hashes, or indicator-based file blocking) prevents further propagation of an attack by blocking potentially malicious processes and files by their hash values.

All EDR vendors block the execution of a process by its hash. Some vendors also prevent the file itself from being accessed or modified, while other vendors ban shared libraries (DLLs). Depending on the vendor and the endpoint system, a couple of minutes of latency may exist between the action and the prevention.

Watch our Auto Block Bad Hashes video for a configuration walkthrough and to learn more.

{% embed url="<https://player.vimeo.com/video/1134411874?amp;app_id=58479&autopause=0&badge=0&byline=0&player_id=0&portrait=0&title=0&h=ede2afbc5e>" %}

**Ready to enable this auto remediation?** **Go to** [**Enable an Auto Remediation in Workbench**](/workbench-setup/auto-remediations/enable-an-auto-remediation-in-workbench.md) **to get started.**

### **Contain Hosts** <a href="#h_01hz5c2axyj8rgnvfavbys88g9" id="h_01hz5c2axyj8rgnvfavbys88g9"></a>

Host containment (which may be referred to by different vendor technologies as quarantine or isolation) blocks incoming and outgoing network traffic except for the traffic necessary to maintain a connection to the security device console. This allows investigators to continue triaging a device from a security device console, while reducing the risks involved with allowing a compromised device to have continued access to the local network.

Each vendor technology handles host containment differently, but they usually perform the following actions:

* Block all TCP traffic to any IP/ports.
* Block all UDP connections except for those responsible for DNS requests (e.g. UDP/53); DNS/DHCP is generally allowed in order to ensure the bilateral communication between the console and the contained device.
* Allow ARP to ensure MAC addresses can resolve to IP addresses.
* Allow ICMP (ping).
* Terminate active sockets.

Some security devices can also allow connections to an allowed IP list.

Watch our Auto Host Containment video for a walkthrough and to learn more about this remediation action.

{% embed url="<https://player.vimeo.com/video/1134411768?amp;app_id=58479&autopause=0&badge=0&byline=0&player_id=0&portrait=0&title=0&h=078d598549>" %}

**Ready to enable this auto remediation?** **Go to** [**Enable an Auto Remediation in Workbench**](/workbench-setup/auto-remediations/enable-an-auto-remediation-in-workbench.md) **to get started.**

### **Deactivate Access Keys** <a href="#h_01hz5c2axynj0m4sb6wfgaz8xr" id="h_01hz5c2axynj0m4sb6wfgaz8xr"></a>

In response to a suspected security incident in your cloud environment, Expel can automatically deactivate potentially compromised long-term AWS access keys that are tied to AWS IAM users, based on unique access key IDs.

Deactivating keys is a proactive measure that aims to sever the attacker's access point and mitigate the risk of a further data breach or system compromise. The goal is to contain the threat by preventing adversaries from continuing to use these keys to access your cloud resources. When Workbench completes the action, the deactivation occurs immediately in AWS.

**Note**

Expel only automates the deactivation of long-term access keys; we do not delete or rotate keys, because such measures are more destructive and are potentially premature. After your access keys are deactivated, you should rotate the compromised keys via AWS and update all cloud applications and services that require these keys to complete tasks.

**Ready to enable this auto remediation?** **Go to** [**Enable an Auto Remediation in Workbench**](/workbench-setup/auto-remediations/enable-an-auto-remediation-in-workbench.md) **to get started.**

### **Delete Malicious Files** <a href="#h_01hz5c2axyay1nxkt3mabxm921" id="h_01hz5c2axyay1nxkt3mabxm921"></a>

If our SOC analysts identify a malicious file that must be removed, Workbench completes the action automatically after that action is created unless it is specifically called out as a file path or hostname on the deny list. If it is on the deny list, we assign the action to your team and notify you based on your notification preferences.

**Ready to enable this auto remediation?** **Go to** [**Enable an Auto Remediation in Workbench**](/workbench-setup/auto-remediations/enable-an-auto-remediation-in-workbench.md) **to get started.**

### **Delete Registry Key** <a href="#h_01hz5c2axz455wcshc3qm7v9d2" id="h_01hz5c2axz455wcshc3qm7v9d2"></a>

When your Windows-based Crowdstrike environment is threatened in such a way that deleting a malicious registry key is necessary, Workbench completes the action automatically after our SOC analysts make the determination. This is often leveraged when malware is using compromised registry keys to run every time the system starts or a user logs in. The deletion nullifies the threat in seconds, and prevents the malware from regaining control of the system.

**Ready to enable this auto remediation?** **Go to** [**Enable an Auto Remediation in Workbench**](/workbench-setup/auto-remediations/enable-an-auto-remediation-in-workbench.md) **to get started.**

### **Disable Accounts** <a href="#h_01hz5c2axz455wcshc3qm7v9d2" id="h_01hz5c2axz455wcshc3qm7v9d2"></a>

Disabling a user account (which may be referred to by different vendor technologies as blocking user, suspending user, changing user status, removing user from org, or locking user account) prevents further propagation of an attack by targeting a compromised user account's username or email address. As part of automating this action in Workbench, we also log the compromised user out of their existing session. Both of these actions are immediate in the target vendor technology.

Watch our Auto Disable Account video for a configuration walkthrough and to learn more.

{% embed url="<https://player.vimeo.com/video/1134411818?amp;app_id=58479&autopause=0&badge=0&byline=0&player_id=0&portrait=0&title=0&h=94663ed567>" %}

**Ready to enable this auto remediation?** **Go to** [**Enable an Auto Remediation in Workbench**](/workbench-setup/auto-remediations/enable-an-auto-remediation-in-workbench.md) **to get started.**

### **Kill Processes** <a href="#h_01hz5c2axzbe8snapcbds4rypv" id="h_01hz5c2axzbe8snapcbds4rypv"></a>

If our SOC analysts identify a malicious process that must be killed, Workbench completes the action automatically after that action is created unless it is specifically called out as a process path or hostname on the deny list. If it is on the deny list, we assign the action to your team and notify you based on your notification preferences.

**Ready to enable this auto remediation?** **Go to** [**Enable an Auto Remediation in Workbench**](/workbench-setup/auto-remediations/enable-an-auto-remediation-in-workbench.md) **to get started.**

### **Remove Malicious Email** <a href="#h_01hz5c2axztcyb5tz99gved5mm" id="h_01hz5c2axztcyb5tz99gved5mm"></a>

If our SOC analysts identify a malicious email that must be removed, Workbench completes the action automatically after that action is created unless it is specifically called out as an inbox on the deny list. If it is on the deny list, we assign the action to your team and notify you based on your notification preferences.

**Ready to enable this auto remediation?** **Go to** [**Enable an Auto Remediation in Workbench**](/workbench-setup/auto-remediations/enable-an-auto-remediation-in-workbench.md) **to get started.**

### **Reset Credentials** <a href="#id-01j7m2h11k0zab3fp6gfs2418c" id="id-01j7m2h11k0zab3fp6gfs2418c"></a>

Requiring a user to reset their credentials (which may be referred to by different vendor technologies as "expire password", or "force change password on next sign-in") prevents further propagation of an attack by stopping unauthorized access. After this remediation action is taken, the compromised user must authenticate with MFA before creating new credentials. As part of automating this action in Workbench, we also log the compromised user out of their existing session. Both of these actions are immediate in the target vendor technology.

**Ready to enable this auto remediation?** **Go to** [**Enable an Auto Remediation in Workbench**](/workbench-setup/auto-remediations/enable-an-auto-remediation-in-workbench.md) **to get started.**


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.expel.io/workbench-setup/auto-remediations/about-auto-remediations.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
