# Delete file from Elastic XDR

**URL:** <https://discuss.elastic.co/t/delete-file-from-elastic-xdr/371655>\
**Category:** Elastic Security\
**Created:** [December 8, 2024, 2:48pm UTC](https://discuss.elastic.co/t/delete-file-from-elastic-xdr/371655 "2024-12-08T14:48:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Charles\_Nkuna](https://avatars.discourse-cdn.com/v4/letter/c/85e7bf/32.png) [@Charles\_Nkuna](https://discuss.elastic.co/u/Charles_Nkuna)\
**Post date:** [December 8, 2024, 2:48pm UTC](https://discuss.elastic.co/t/delete-file-from-elastic-xdr/371655/1 "2024-12-08T14:48:07Z")

</div>

Hello everyone,

Is it possible or if there's way to delete a file from the console detected by Elastic defend.?

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [December 11, 2024, 8:12am UTC](https://discuss.elastic.co/t/delete-file-from-elastic-xdr/371655/2 "2024-12-11T08:12:53Z")

</div>

`execute` action can be used for that

---

<div class="post-metadata">

**Author:** ![Charles\_Nkuna](https://avatars.discourse-cdn.com/v4/letter/c/85e7bf/32.png) [@Charles\_Nkuna](https://discuss.elastic.co/u/Charles_Nkuna)\
**Post date:** [December 12, 2024, 6:22am UTC](https://discuss.elastic.co/t/delete-file-from-elastic-xdr/371655/3 "2024-12-12T06:22:11Z")

</div>

Hi @lesio

Thanks for the feedback.

and what will be the command associating execute

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [December 12, 2024, 1:07pm UTC](https://discuss.elastic.co/t/delete-file-from-elastic-xdr/371655/4 "2024-12-12T13:07:34Z")

</div>

Yes you'll have to use OS specific command, all is documented here

> **[Endpoint response actions | Serverless | Elastic](https://www.elastic.co/guide/en/serverless/current/security-response-actions.html#security-response-actions-execute)**

---

<div class="post-metadata">

**Author:** ![Charles\_Nkuna](https://avatars.discourse-cdn.com/v4/letter/c/85e7bf/32.png) [@Charles\_Nkuna](https://discuss.elastic.co/u/Charles_Nkuna)\
**Post date:** [January 9, 2025, 6:08am UTC](https://discuss.elastic.co/t/delete-file-from-elastic-xdr/371655/5 "2025-01-09T06:08:56Z")

</div>

Hi @lesio

Thanks for the feedback and the Link provided.

i went through the documents but still its still not clear how to utilize execute action to delete the file.

If possible can you please share example on how to delete the file using execute action command?

Thanks.

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [January 21, 2025, 10:55am UTC](https://discuss.elastic.co/t/delete-file-from-elastic-xdr/371655/6 "2025-01-21T10:55:41Z")

</div>

> [@Charles\_Nkuna](#):
>
> detected by Elastic defend

Hello, I re-read your original question. I'm not sure what do you mean by "detected". If Endpoint works in prevention mode such detected file gets quarantined.

However if Endpoint works in detection only mode, the file will be left intact. On which OS do you experience problems with it? Indeed you might need to leverage additional shell commands to understand the file permission and utilize `runas`, depending on your environment.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 18, 2025, 10:56am UTC](https://discuss.elastic.co/t/delete-file-from-elastic-xdr/371655/7 "2025-02-18T10:56:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
