<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need Clear idea on XDR action on file in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/need-clear-idea-on-xdr-action-on-file/m-p/551746#M4865</link>
    <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/304582"&gt;@Venkatesh_Konar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope you are doing well. From your query I understand you would like to know what happens to a file once it is detected by Cortex XDR to be malicious. Please note that the action taken on the files depends on the Malware security profile configurations.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please check the malware profile which is configured for the device in question and see if it is set to Block, Report or Disabled. If it is set to Block then please check what action is to be taken on the file such as Quarantine the file or delete it. Please find the Knowledge base articles provided below on Malware security profile:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-a-New-Malware-Security-Profile" target="_self"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-a-New-Malware-Security-Profile&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also please find the documentation on how to manage Quarantine files below, thank you:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-Quarantined-Files" target="_self"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-Quarantined-Files&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this answers your query, please reply back to this thread if there is anything else I can assist you with on this query. If you find this answer to be useful, please mark it as a solution, thank you.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 31 Jul 2023 10:39:41 GMT</pubDate>
    <dc:creator>abdrahman</dc:creator>
    <dc:date>2023-07-31T10:39:41Z</dc:date>
    <item>
      <title>Need Clear idea on XDR action on file</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/need-clear-idea-on-xdr-action-on-file/m-p/551589#M4857</link>
      <description>&lt;P&gt;Dear All ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once XDR taken action on a set of files which seems to be suspicious . Apart from Wildfire verdict , its also shows XDR action like Detected , Prevented (blocked ) .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can I confirm&amp;nbsp;Actual Action by XDR is Quarantine / Cleaned&amp;nbsp; / Deleted ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 13:38:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/need-clear-idea-on-xdr-action-on-file/m-p/551589#M4857</guid>
      <dc:creator>Venkatesh_Konar</dc:creator>
      <dc:date>2023-07-28T13:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: Need Clear idea on XDR action on file</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/need-clear-idea-on-xdr-action-on-file/m-p/551746#M4865</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/304582"&gt;@Venkatesh_Konar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope you are doing well. From your query I understand you would like to know what happens to a file once it is detected by Cortex XDR to be malicious. Please note that the action taken on the files depends on the Malware security profile configurations.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please check the malware profile which is configured for the device in question and see if it is set to Block, Report or Disabled. If it is set to Block then please check what action is to be taken on the file such as Quarantine the file or delete it. Please find the Knowledge base articles provided below on Malware security profile:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-a-New-Malware-Security-Profile" target="_self"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-a-New-Malware-Security-Profile&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also please find the documentation on how to manage Quarantine files below, thank you:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-Quarantined-Files" target="_self"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-Quarantined-Files&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this answers your query, please reply back to this thread if there is anything else I can assist you with on this query. If you find this answer to be useful, please mark it as a solution, thank you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 10:39:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/need-clear-idea-on-xdr-action-on-file/m-p/551746#M4865</guid>
      <dc:creator>abdrahman</dc:creator>
      <dc:date>2023-07-31T10:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: Need Clear idea on XDR action on file</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/need-clear-idea-on-xdr-action-on-file/m-p/551775#M4868</link>
      <description>&lt;P&gt;Hi Venkatesh_Konar,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRIKE&gt;Just to add on to what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/290451"&gt;@abdrahman&lt;/a&gt;&amp;nbsp;already said, if the file was also quarantined in addition to being blocked, the action will be reported as Prevented (quarantined), but whether this is done is based on your Malware Profile configuration.&amp;nbsp; &lt;/STRIKE&gt;Note, XDR does not automatically delete files, only optionally quarantine them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Correction, this is not shown as a part of the alert action information.&amp;nbsp; You can confirm this by going to the Action Center and clicking on File Quarantine to see the list of currently quarantined files on all endpoints.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 13:55:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/need-clear-idea-on-xdr-action-on-file/m-p/551775#M4868</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2023-08-01T13:55:02Z</dc:date>
    </item>
  </channel>
</rss>

