<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File lookup in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-lookup/m-p/529610#M3541</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/251467"&gt;@VineethArumulla&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I understand you intend to lookup for presence of files or hashes in the endpoints using Cortex XDR. This is possible using the host insights "File Search" feature. If you have Cortex XDR Pro Per Endpoints license and Host-Insights add-on license, then you need to enable "Host Insights Capabilities".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-02-02 at 8.44.12 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47600i3C59014F95A5725A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-02-02 at 8.44.12 PM.png" alt="Screenshot 2023-02-02 at 8.44.12 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If this enabled, then you can search for files by file paths or file hashes under the "Action Center" items. Select the file path with(or without) wildcards. You should be able to find the details for the same.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-02-02 at 8.47.18 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47601i4597445A552AE741/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-02-02 at 8.47.18 PM.png" alt="Screenshot 2023-02-02 at 8.47.18 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alternatively, if you do not have the add-on license, then you can query for file names using Cortex XDR query builder.&amp;nbsp; This would only happen provided if the file activity has been reported by Cortex XDR.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Feb 2023 13:22:12 GMT</pubDate>
    <dc:creator>neelrohit</dc:creator>
    <dc:date>2023-02-02T13:22:12Z</dc:date>
    <item>
      <title>File lookup</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-lookup/m-p/529596#M3540</link>
      <description>&lt;P&gt;Is it possible to check if a file is present on any system in network through Cortex XDR based on file name or the hash value of the file.&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt; &lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 10:48:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-lookup/m-p/529596#M3540</guid>
      <dc:creator>VineethArumulla</dc:creator>
      <dc:date>2023-02-02T10:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: File lookup</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-lookup/m-p/529610#M3541</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/251467"&gt;@VineethArumulla&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I understand you intend to lookup for presence of files or hashes in the endpoints using Cortex XDR. This is possible using the host insights "File Search" feature. If you have Cortex XDR Pro Per Endpoints license and Host-Insights add-on license, then you need to enable "Host Insights Capabilities".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-02-02 at 8.44.12 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47600i3C59014F95A5725A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-02-02 at 8.44.12 PM.png" alt="Screenshot 2023-02-02 at 8.44.12 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If this enabled, then you can search for files by file paths or file hashes under the "Action Center" items. Select the file path with(or without) wildcards. You should be able to find the details for the same.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-02-02 at 8.47.18 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47601i4597445A552AE741/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-02-02 at 8.47.18 PM.png" alt="Screenshot 2023-02-02 at 8.47.18 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alternatively, if you do not have the add-on license, then you can query for file names using Cortex XDR query builder.&amp;nbsp; This would only happen provided if the file activity has been reported by Cortex XDR.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 13:22:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-lookup/m-p/529610#M3541</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-02-02T13:22:12Z</dc:date>
    </item>
  </channel>
</rss>

