<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XDR command line scan in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-command-line-scan/m-p/446444#M1220</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191288"&gt;@PaulDownes&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #222222; font-family: Arial, Helvetica, sans-serif; font-size: small; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;In order to get better traction for this, I have moved your query to the Cortex area.&lt;/SPAN&gt;&lt;BR style="color: #222222; font-family: Arial, Helvetica, sans-serif; font-size: small; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;SPAN style="color: #222222; font-family: Arial, Helvetica, sans-serif; font-size: small; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;I would recommend that you visit this area to see your discussion and others on Cortex.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #222222; font-family: Arial, Helvetica, sans-serif; font-size: small; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #222222; font-family: Arial, Helvetica, sans-serif; font-size: small; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Tue, 09 Nov 2021 13:02:48 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2021-11-09T13:02:48Z</dc:date>
    <item>
      <title>XDR command line scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-command-line-scan/m-p/445496#M1219</link>
      <description>&lt;P&gt;Hi All, I've been looking at the functionality of the cytool command line and cannot find a way to scan a particular file, which is available if you right click the file in Windows. Can anyone tell me if the ability to scan an individual file, or folder available from command line in XDR client?&lt;/P&gt;&lt;P&gt;Thanks, Paul&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 15:09:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-command-line-scan/m-p/445496#M1219</guid>
      <dc:creator>PaulDownes</dc:creator>
      <dc:date>2021-11-04T15:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: XDR command line scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-command-line-scan/m-p/446444#M1220</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191288"&gt;@PaulDownes&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #222222; font-family: Arial, Helvetica, sans-serif; font-size: small; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;In order to get better traction for this, I have moved your query to the Cortex area.&lt;/SPAN&gt;&lt;BR style="color: #222222; font-family: Arial, Helvetica, sans-serif; font-size: small; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;SPAN style="color: #222222; font-family: Arial, Helvetica, sans-serif; font-size: small; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;I would recommend that you visit this area to see your discussion and others on Cortex.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #222222; font-family: Arial, Helvetica, sans-serif; font-size: small; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #222222; font-family: Arial, Helvetica, sans-serif; font-size: small; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 09 Nov 2021 13:02:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-command-line-scan/m-p/446444#M1220</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2021-11-09T13:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: XDR command line scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-command-line-scan/m-p/446450#M1221</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191288"&gt;@PaulDownes&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The scan malware option is not part of the cytool commands.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are some alternatives&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;cytool fileinfo c:\path\to\app1.exe - process needs to be known to WF/LA&lt;OL&gt;&lt;LI&gt;this will give you information about app1.exe. you want to look for the File SHA256 value&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;cytool wf query app1_sha256_value&lt;OL&gt;&lt;LI&gt;If you do not get a result, it means that WF/LA do not know it. At this point, you first need to upload the file to WF. You can do that by scanning the file using the mouse&lt;/LI&gt;&lt;LI&gt;you could use cytool imageprep. this will look at all the volumes are upload to WF those that are unknown. This operation could take quite some time, at least the first time executed. Later imageprep scans, would take less time as only those new unknown executables will be uploaded to WF.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 13:19:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-command-line-scan/m-p/446450#M1221</guid>
      <dc:creator>fmoixsante</dc:creator>
      <dc:date>2021-11-09T13:19:02Z</dc:date>
    </item>
    <item>
      <title>Re: XDR command line scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-command-line-scan/m-p/446490#M1222</link>
      <description>&lt;P&gt;looks like looking at the official docs you can just start a scan:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/5-0/cortex-xdr-agent-admin/traps-agent-for-windows/troubleshoot-traps-for-windows/cytool.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/5-0/cortex-xdr-agent-admin/traps-agent-for-windows/troubleshoot-traps-for-windows/cytool.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would however confirm with the tac&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 15:00:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-command-line-scan/m-p/446490#M1222</guid>
      <dc:creator>P.Jacob</dc:creator>
      <dc:date>2021-11-09T15:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: XDR command line scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-command-line-scan/m-p/446999#M1229</link>
      <description>&lt;P&gt;Thanks folks, all very helpful. I'm going to accept Fmoixsante's suggestion about the imageprep scan as the accepted solution, might be able to run with that. If there was something flagged on the client machine to say the scan marked the file safe / unsafe, I could possibly use that to trigger a subsequent action to admins also. I appreciate the insights from you all, thanks again.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 14:22:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-command-line-scan/m-p/446999#M1229</guid>
      <dc:creator>PaulDownes</dc:creator>
      <dc:date>2021-11-11T14:22:53Z</dc:date>
    </item>
  </channel>
</rss>

