Additional Actions Pending

Microsoft.FEP.SecurityRootCause.MalwareActivity.PendingAdditionalActions.Monitor (DependencyMonitor)

This monitor tracks whether additional actions must be performed after malware has been blocked and removed from a computer.

Knowledge Base article:

Summary

Some types of malware may require additional actions to confirm their complete removal from the computer.

Configuration

It is advised to keep this alert turned on with the default configuration.

Resolutions

Follow the alert description. You may be required to launch a full scan, run an offline scan tool, perform manual steps, or restart the computer. You can restart a computer by using a recovery task in Health Explorer.

Element properties:

TargetMicrosoft.FEP.SecurityRootCause.MalwareActivity
Parent MonitorSystem.Health.SecurityState
AlgorithmWorstOf
Source MonitorMicrosoft.FEP.ProtectedServer.PendingAdditionalActions.Monitor
RelationshipMicrosoft.FEP.MalwareActivityReferencesProtectedServer
CategoryCustom
EnabledTrue
Alert GenerateFalse
Alert Auto ResolveFalse
RemotableTrue
AccessibilityPublic

Source Code:

<DependencyMonitor ID="Microsoft.FEP.SecurityRootCause.MalwareActivity.PendingAdditionalActions.Monitor" Accessibility="Public" Enabled="true" Target="FEPLibrary!Microsoft.FEP.SecurityRootCause.MalwareActivity" ParentMonitorID="Health!System.Health.SecurityState" Remotable="true" Priority="Normal" RelationshipType="FEPLibrary!Microsoft.FEP.MalwareActivityReferencesProtectedServer" MemberMonitor="Microsoft.FEP.ProtectedServer.PendingAdditionalActions.Monitor">
<Category>Custom</Category>
<Algorithm>WorstOf</Algorithm>
<MemberUnAvailable>Error</MemberUnAvailable>
</DependencyMonitor>