<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Quarantine not working in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantine-not-working/m-p/330220#M141</link>
    <description>&lt;P&gt;well its works with other endpoints&lt;/P&gt;</description>
    <pubDate>Thu, 28 May 2020 07:33:30 GMT</pubDate>
    <dc:creator>Marsooq_A</dc:creator>
    <dc:date>2020-05-28T07:33:30Z</dc:date>
    <item>
      <title>Quarantine not working</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantine-not-working/m-p/329645#M129</link>
      <description>&lt;P&gt;Hi Team&lt;/P&gt;&lt;P&gt;We have enabled quarantine for wildfire and local analysis malware verdict. When initiating malware scan from cortex xdr cloud t, the malware's are getting detected and but those are not getting quarantined.Can anyone advice is this how it works?&lt;/P&gt;</description>
      <pubDate>Sat, 23 May 2020 16:52:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantine-not-working/m-p/329645#M129</guid>
      <dc:creator>Marsooq_A</dc:creator>
      <dc:date>2020-05-23T16:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: Quarantine not working</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantine-not-working/m-p/329912#M130</link>
      <description>&lt;P&gt;Can you post a screenshot of the &lt;STRONG&gt;Portable Executable and DLL Examination&lt;/STRONG&gt; portion of your &lt;STRONG&gt;malware&lt;/STRONG&gt; profile?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dfalcon_0-1590513998705.png" style="width: 658px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25829i8393F73A6D10A329/image-dimensions/658x482/is-moderation-mode/true?v=v2" width="658" height="482" role="button" title="dfalcon_0-1590513998705.png" alt="dfalcon_0-1590513998705.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 17:27:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantine-not-working/m-p/329912#M130</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-05-26T17:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: Quarantine not working</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantine-not-working/m-p/329920#M133</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_3.png" style="width: 895px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25831iF67C0EBA7B25EF42/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot_3.png" alt="Screenshot_3.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 17:41:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantine-not-working/m-p/329920#M133</guid>
      <dc:creator>Marsooq_A</dc:creator>
      <dc:date>2020-05-26T17:41:18Z</dc:date>
    </item>
    <item>
      <title>Re: Quarantine not working</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantine-not-working/m-p/329923#M134</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/141755"&gt;@Marsooq_A&lt;/a&gt;-&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Just to confirm.&amp;nbsp; When you go to &lt;STRONG&gt;Endpoint Management&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Endpoint Administration&lt;/STRONG&gt;, select an endpoint that is failing, &lt;STRONG&gt;right-click&lt;/STRONG&gt;&amp;nbsp;and select &lt;STRONG&gt;View Endpoint Policy&lt;/STRONG&gt; -- can you see the profile with quarantine enabled applied to the specific machine?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dfalcon_0-1590515675290.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25832i5DA87A07C2525277/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="dfalcon_0-1590515675290.png" alt="dfalcon_0-1590515675290.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 17:55:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantine-not-working/m-p/329923#M134</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-05-26T17:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: Quarantine not working</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantine-not-working/m-p/329924#M135</link>
      <description>&lt;P&gt;Yes , I could see the same profile in the policy and this has been confirmed several times.&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 18:02:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantine-not-working/m-p/329924#M135</guid>
      <dc:creator>Marsooq_A</dc:creator>
      <dc:date>2020-05-26T18:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: Quarantine not working</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantine-not-working/m-p/329925#M136</link>
      <description>&lt;P&gt;Next thing I would check is the agent logs after a quarantine attempt.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/wildfire/8-1/wildfire-admin/submit-files-for-wildfire-analysis/verify-wildfire-submissions/test-a-sample-malware-file" target="_blank"&gt;https://docs.paloaltonetworks.com/wildfire/8-1/wildfire-admin/submit-files-for-wildfire-analysis/verify-wildfire-submissions/test-a-sample-malware-file&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can use this test PE to trigger a quarantine event.&amp;nbsp; After the event is complete, open the log file, scroll to the bottom and look for any messages associated with the quarantine attempt.&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 18:05:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantine-not-working/m-p/329925#M136</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-05-26T18:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: Quarantine not working</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantine-not-working/m-p/330220#M141</link>
      <description>&lt;P&gt;well its works with other endpoints&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 07:33:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantine-not-working/m-p/330220#M141</guid>
      <dc:creator>Marsooq_A</dc:creator>
      <dc:date>2020-05-28T07:33:30Z</dc:date>
    </item>
  </channel>
</rss>

