<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to use interactive script mode Run Kansa investigation powershell in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-use-interactive-script-mode-run-kansa-investigation/m-p/543525#M4446</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;does anyone know&lt;/P&gt;
&lt;P&gt;How to add investigation powershell to the Agent script Library of XDR Action Center. That I can choose it to do incident investigation when using XDR interactive script mode&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;div class="video-embed-center video-embed"&gt;&lt;iframe class="embedly-embed" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FXF6r9ugQirg%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DXF6r9ugQirg&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FXF6r9ugQirg%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" width="400" height="225" scrolling="no" title="Kansa - A PowerShell Based IR Framework" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture;" allowfullscreen="true"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 26 May 2023 15:34:05 GMT</pubDate>
    <dc:creator>kentwuhc</dc:creator>
    <dc:date>2023-05-26T15:34:05Z</dc:date>
    <item>
      <title>How to use interactive script mode Run Kansa investigation powershell</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-use-interactive-script-mode-run-kansa-investigation/m-p/543525#M4446</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;does anyone know&lt;/P&gt;
&lt;P&gt;How to add investigation powershell to the Agent script Library of XDR Action Center. That I can choose it to do incident investigation when using XDR interactive script mode&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;div class="video-embed-center video-embed"&gt;&lt;iframe class="embedly-embed" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FXF6r9ugQirg%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DXF6r9ugQirg&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FXF6r9ugQirg%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" width="400" height="225" scrolling="no" title="Kansa - A PowerShell Based IR Framework" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture;" allowfullscreen="true"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 15:34:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-use-interactive-script-mode-run-kansa-investigation/m-p/543525#M4446</guid>
      <dc:creator>kentwuhc</dc:creator>
      <dc:date>2023-05-26T15:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to use interactive script mode Run Kansa investigation powershell</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-use-interactive-script-mode-run-kansa-investigation/m-p/543787#M4450</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/228205"&gt;@kentwuhc&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Agent Script library allows XDR management console users (with the right privileges) to execute Python scripts on the endpoint. It might not be a great user experience for you to perform investigations in the way you are aiming for. Usually, investigators would isolate an endpoint, perform a clone of the asset and run investigations off the clone to preserve the integrity of the asset.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can use the script titled "execute_commands" in Agent Script library as a template to create your own script to run Powershell commands on the endpoint by fetching the powershell project off a shared drive. It won't have that level of interactivity, though.&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 07:40:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-use-interactive-script-mode-run-kansa-investigation/m-p/543787#M4450</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2023-05-29T07:40:05Z</dc:date>
    </item>
    <item>
      <title>回复： How to use interactive script mode Run Kansa investigation powershell</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-use-interactive-script-mode-run-kansa-investigation/m-p/546038#M4574</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class="UserName lia-user-name lia-user-rank-L5-Sessionator lia-component-message-view-widget-author-username"&gt;&lt;A id="link_15" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661" target="_self" aria-label="查看 bbarmanroy 的个人资料"&gt;&lt;SPAN class=""&gt;Bbarmanroy&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Thank you for your reply because our Agent in different locations It can't be there to investigate every PC in different locations&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 14:54:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-use-interactive-script-mode-run-kansa-investigation/m-p/546038#M4574</guid>
      <dc:creator>kentwuhc</dc:creator>
      <dc:date>2023-06-14T14:54:59Z</dc:date>
    </item>
  </channel>
</rss>

