<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Anti-ransomware aggressive mode files backup issues in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/anti-ransomware-aggressive-mode-files-backup-issues/m-p/532172#M3701</link>
    <description>&lt;P&gt;Hi to everyone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have anti-ransomware feature set in "aggressive mode"&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The aggresive mode files cause the backup software of PCs to fail, and thousands of "There was a general error processing this file. Please retry it and if the problem persists, contact your system administrator." issues per computer in the backup console.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any way to avoid this without disabling the aggressive mode?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone experienced similar problems?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 24 Feb 2023 11:48:36 GMT</pubDate>
    <dc:creator>Edgar_Lapuerta</dc:creator>
    <dc:date>2023-02-24T11:48:36Z</dc:date>
    <item>
      <title>Anti-ransomware aggressive mode files backup issues</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/anti-ransomware-aggressive-mode-files-backup-issues/m-p/532172#M3701</link>
      <description>&lt;P&gt;Hi to everyone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have anti-ransomware feature set in "aggressive mode"&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The aggresive mode files cause the backup software of PCs to fail, and thousands of "There was a general error processing this file. Please retry it and if the problem persists, contact your system administrator." issues per computer in the backup console.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any way to avoid this without disabling the aggressive mode?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone experienced similar problems?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 11:48:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/anti-ransomware-aggressive-mode-files-backup-issues/m-p/532172#M3701</guid>
      <dc:creator>Edgar_Lapuerta</dc:creator>
      <dc:date>2023-02-24T11:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-ransomware aggressive mode files backup issues</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/anti-ransomware-aggressive-mode-files-backup-issues/m-p/532354#M3711</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/266300"&gt;@Edgar_Lapuerta&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LIVEcommunity.&amp;nbsp; I understand you're having issues with backing up in your environment with your ransomware feature set to "aggressive mode".&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2023-02-27 at 8.26.48 AM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48204i157BA42FA8D84EBA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2023-02-27 at 8.26.48 AM.png" alt="Screen Shot 2023-02-27 at 8.26.48 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please not that when Protection Mode is set to Aggressive you're greeting this with warning "&lt;SPAN&gt;Aggressive Protection Mode&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;may have an impact on applications in your environment and users may view decoy files that they would not see in Normal mode."&amp;nbsp; An important things to remember is what ransomware activity looks like in the wild.&amp;nbsp; Threat Actors gain access and then attempt to exfiltrate data in numerous ways.&amp;nbsp; They often use legitimate software found in your environment to help them achieve their goal and remain unseen.&amp;nbsp; Most backup solutions tend to work in a similiar way.&amp;nbsp; By transferring large amounts of data from several endpoints it's often hard to tell what is legitimate backup activity and what is data exfiltration.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;For this particular issue I'd recommend reaching out to you backup vendor and asking for exceptions you can add to Cortex XDR to allow it to run.&amp;nbsp; If the vendor is unable to help you can reach out to &lt;A href="https://support.paloaltonetworks.com/Support/Index" target="_self"&gt;support and ask for a Support Exclusion&lt;/A&gt;.&amp;nbsp; I'd recommend either of these courses of action with one caveat.&amp;nbsp; If you add an exception for this software you may lose visibility if any threat actor is able to use the same software for data exfiltration.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this information helps.&amp;nbsp; Please reach out if you have any other issues we may be able to help with and have a great day!&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2023 14:34:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/anti-ransomware-aggressive-mode-files-backup-issues/m-p/532354#M3711</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-02-27T14:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-ransomware aggressive mode files backup issues</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/anti-ransomware-aggressive-mode-files-backup-issues/m-p/532362#M3714</link>
      <description>&lt;P&gt;Hy Anlynch,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your answer, but I think I didn't explain myself well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The backup software is running OK, but it is struggling to backup the Cortex XDR decoy files.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are many files in different folders that backup software can not copy to the cloud.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Backup.PNG" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48205i7A0A9A2C66EC4D35/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Backup.PNG" alt="Backup.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;General backup is working OK, but logs are full of these errors and some backup clients crash from time to time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any suggestions?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2023 16:00:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/anti-ransomware-aggressive-mode-files-backup-issues/m-p/532362#M3714</guid>
      <dc:creator>Edgar_Lapuerta</dc:creator>
      <dc:date>2023-02-27T16:00:06Z</dc:date>
    </item>
  </channel>
</rss>

