<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File search and destroy in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-search-and-destroy/m-p/557027#M5105</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206335"&gt;@RamyashreeMada&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out to live community. Please note that we do have a feature known as search and destroy malicious files in Cortex XDR.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This feature helps you in searching &lt;SPAN&gt;for specific files according to the file hash, the file full path, or a partial path using regex parameters from the Action Center or the Query Builder. After you find the file, you can quickly select it in the search results and destroy the file by hash or by path. You can also destroy a file from the Action Center, without performing a search, if you know the path or hash. When you destroy a file by hash, all the file instances on the endpoint are removed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For further details please find the Document provided below with detail steps on how to configure&amp;nbsp;this feature. Thank you:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Search-and-Destroy-Malicious-Files" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Search-and-Destroy-Malicious-Files&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you find this answer relevant to resolve your query, then please mark this as a Solution. Thank you.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Sep 2023 16:26:13 GMT</pubDate>
    <dc:creator>abdrahman</dc:creator>
    <dc:date>2023-09-07T16:26:13Z</dc:date>
    <item>
      <title>File search and destroy</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-search-and-destroy/m-p/556996#M5104</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are unable to delete certain file due to the error "Access is denied".&lt;/P&gt;
&lt;P&gt;Is there any other way to delete these files.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 12:25:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-search-and-destroy/m-p/556996#M5104</guid>
      <dc:creator>RamyashreeMada</dc:creator>
      <dc:date>2023-09-07T12:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: File search and destroy</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-search-and-destroy/m-p/557027#M5105</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206335"&gt;@RamyashreeMada&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out to live community. Please note that we do have a feature known as search and destroy malicious files in Cortex XDR.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This feature helps you in searching &lt;SPAN&gt;for specific files according to the file hash, the file full path, or a partial path using regex parameters from the Action Center or the Query Builder. After you find the file, you can quickly select it in the search results and destroy the file by hash or by path. You can also destroy a file from the Action Center, without performing a search, if you know the path or hash. When you destroy a file by hash, all the file instances on the endpoint are removed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For further details please find the Document provided below with detail steps on how to configure&amp;nbsp;this feature. Thank you:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Search-and-Destroy-Malicious-Files" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Search-and-Destroy-Malicious-Files&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you find this answer relevant to resolve your query, then please mark this as a Solution. Thank you.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 16:26:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-search-and-destroy/m-p/557027#M5105</guid>
      <dc:creator>abdrahman</dc:creator>
      <dc:date>2023-09-07T16:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: File search and destroy</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-search-and-destroy/m-p/557401#M5118</link>
      <description>&lt;P&gt;The response is more general and specific to the issue presented by the user. I think you get access denied because the file is already being used or locked by windows, the best way to delete is from software center. But don't take my word for it, I'm still researching this issue too. I was also under the impression that Cortex xdr agent has elevated privileges, so it should not be permission level issues.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 18:12:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-search-and-destroy/m-p/557401#M5118</guid>
      <dc:creator>MosR</dc:creator>
      <dc:date>2023-09-11T18:12:48Z</dc:date>
    </item>
  </channel>
</rss>

