<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR malware scan in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-malware-scan/m-p/536430#M3937</link>
    <description>&lt;P&gt;Hello ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know the difference between the Malware scan initiated from console and Scan initiated by user locally for all drive? Does cortex XDR also scans the memory and registries in the full scan initiated? and how long it should take a system or agent to timeout the scan it it continues in progress for long time.&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 25 Mar 2023 13:52:40 GMT</pubDate>
    <dc:creator>TejasPatil</dc:creator>
    <dc:date>2023-03-25T13:52:40Z</dc:date>
    <item>
      <title>Cortex XDR malware scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-malware-scan/m-p/536430#M3937</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know the difference between the Malware scan initiated from console and Scan initiated by user locally for all drive? Does cortex XDR also scans the memory and registries in the full scan initiated? and how long it should take a system or agent to timeout the scan it it continues in progress for long time.&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Mar 2023 13:52:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-malware-scan/m-p/536430#M3937</guid>
      <dc:creator>TejasPatil</dc:creator>
      <dc:date>2023-03-25T13:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR malware scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-malware-scan/m-p/536522#M3941</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/274255"&gt;@TejasPatil&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cortex XDR server initiated malware scans vs user initiated scans work on the same logic of examination. The difference is between the coverage of scan and capability to abort. The server initiated scans are full system scans, while the user initiated scans can be local to specific files/folder/drives. Also the server initiated scans cannot be aborted by the end user, while the endpoint initiated scans can be aborted by end user.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, there is no ETA to completion for malware scans. For more details and insights on the same, we have a webinar scheduled on 29th of March, 2023, which is based on Active scanning.&lt;/P&gt;
&lt;P&gt;Appreciate your presence to have clarification in detail. I am assuming you are in EMEA/JAPAC region and have hyperlinked the image with the registration link for the same. This email was sent to our customers.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://paloaltonetworks.zoom.us/webinar/register/4016521233424/WN_EWW6xEwGT56wBDijcYFvcQ" target="_self"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-03-27 at 10.22.20 AM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49030i2D82A534B105CF6E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-03-27 at 10.22.20 AM.png" alt="Screenshot 2023-03-27 at 10.22.20 AM.png" /&gt;&lt;/span&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 02:24:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-malware-scan/m-p/536522#M3941</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-03-27T02:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR malware scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-malware-scan/m-p/536586#M3945</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/142551"&gt;@neelrohit&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for response. Yes i will be joining the webinar for this topic.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you you please help me to understand the line "&lt;SPAN&gt;&lt;STRONG&gt;&lt;EM&gt;The server initiated scans are full system scans, while the user initiated scans can be local to specific files/folder/drives.&lt;/EM&gt;&lt;/STRONG&gt;"&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;for example in 1 machine there is only 1 drive then by initiating scan from user end for that drive will also be system full scan other than criteria of abortion of scan ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 12:02:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-malware-scan/m-p/536586#M3945</guid>
      <dc:creator>TejasPatil</dc:creator>
      <dc:date>2023-03-27T12:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR malware scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-malware-scan/m-p/536588#M3946</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/274255"&gt;@TejasPatil&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Indeed your understanding is correct!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the malware scan is initiated on an endpoint by right clicking on its drive letters and if the endpoint happens to have only one drive partition, that is more or less equivalent to a full system scan. What however applicable fact is that the end user will have the capability to abort it if the user has been provided the access to the agent console. Screenshot below:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-03-27 at 8.11.53 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49038i2DB14151CBEA9C88/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-03-27 at 8.11.53 PM.png" alt="Screenshot 2023-03-27 at 8.11.53 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The abort is something that would not be possible when the scans are configured to be periodic or server initiated.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps! Please mark the response as "Accept as Solution" if it resolves your query.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 12:19:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-malware-scan/m-p/536588#M3946</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-03-27T12:19:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR malware scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-malware-scan/m-p/547094#M4639</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/142551"&gt;@neelrohit&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One more query on this topic, Does scan initiated locally from Cytool scan start command is different from Malware scan initiated from backend? other than its method of starting the scan&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 02:17:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-malware-scan/m-p/547094#M4639</guid>
      <dc:creator>TejasPatil</dc:creator>
      <dc:date>2023-06-24T02:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR malware scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-malware-scan/m-p/547142#M4641</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/274255"&gt;@TejasPatil&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your understanding is correct.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 16:23:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-malware-scan/m-p/547142#M4641</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-06-24T16:23:31Z</dc:date>
    </item>
  </channel>
</rss>

