<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active Scanning on Endpoints in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/active-scanning-on-endpoints/m-p/521963#M3171</link>
    <description>&lt;P&gt;Hi RamyashreeMada,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cortex XDR protection capabilities only apply when processes execute, we do not scan files on-write.&amp;nbsp; The periodic scan feature allows you to identify malicious files stored on disk which are not attempting to execute.&lt;/P&gt;</description>
    <pubDate>Tue, 22 Nov 2022 03:06:26 GMT</pubDate>
    <dc:creator>afurze</dc:creator>
    <dc:date>2022-11-22T03:06:26Z</dc:date>
    <item>
      <title>Active Scanning on Endpoints</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/active-scanning-on-endpoints/m-p/521690#M3165</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We intend to perform scheduled scanning on all endpoints. So we wondered if active scanning was required on all endpoints repeatedly, or if cortex developed its own scan whenever a new file was created or added to the system.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 13:56:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/active-scanning-on-endpoints/m-p/521690#M3165</guid>
      <dc:creator>RamyashreeMada</dc:creator>
      <dc:date>2022-11-18T13:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: Active Scanning on Endpoints</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/active-scanning-on-endpoints/m-p/521963#M3171</link>
      <description>&lt;P&gt;Hi RamyashreeMada,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cortex XDR protection capabilities only apply when processes execute, we do not scan files on-write.&amp;nbsp; The periodic scan feature allows you to identify malicious files stored on disk which are not attempting to execute.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 03:06:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/active-scanning-on-endpoints/m-p/521963#M3171</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2022-11-22T03:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Active Scanning on Endpoints</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/active-scanning-on-endpoints/m-p/524738#M3279</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Can we run malware scan based on IP range?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2022 09:12:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/active-scanning-on-endpoints/m-p/524738#M3279</guid>
      <dc:creator>RamyashreeMada</dc:creator>
      <dc:date>2022-12-21T09:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: Active Scanning on Endpoints</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/active-scanning-on-endpoints/m-p/524892#M3285</link>
      <description>&lt;P&gt;RamyashreeMada,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are two ways you can run Malware scans in XDR, documented in our &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Scan-an-Endpoint-for-Malware" target="_self"&gt;Tech Docs&lt;/A&gt;.&amp;nbsp; First, you can set up periodic malware scans via the Malware Protection profile.&amp;nbsp; If you want to run an ad-hoc scan, you can use an action, from Incident Response -&amp;gt; Action Center or on the All Endpoints page by right clicking the endpoint.&amp;nbsp; From either location, you can filter to find endpoints you want to target, for example, using IP address in a range, and then execute a malware scan action.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2022 20:26:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/active-scanning-on-endpoints/m-p/524892#M3285</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2022-12-22T20:26:41Z</dc:date>
    </item>
  </channel>
</rss>

