<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Quarantining files about 300 MB / Hunting big Files in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantining-files-about-300-mb-hunting-big-files/m-p/557416#M5120</link>
    <description>&lt;P&gt;Yes, if you need the files at the moment, it needs to be online. If it is not, the task is hold as "Pending" until the client connects again with the console.&lt;/P&gt;
&lt;P&gt;I tried to retrieve files with the route&amp;nbsp;&lt;SPAN&gt;%PROGRAMDATA%\Cyvera\QuarantineV2\*.* and all came encrypted.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;JM&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Sep 2023 19:08:56 GMT</pubDate>
    <dc:creator>jmazzeo</dc:creator>
    <dc:date>2023-09-11T19:08:56Z</dc:date>
    <item>
      <title>Quarantining files about 300 MB / Hunting big Files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantining-files-about-300-mb-hunting-big-files/m-p/557248#M5113</link>
      <description>&lt;P&gt;Hello dear community,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what happens with quarantined files, which have 300 MB?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can't download it from the action center like I am used to.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, I saw they are moved to&amp;nbsp;&lt;CODE class="filename hljs language-shell"&gt;&lt;SPAN class="hljs-meta prompt_"&gt;%&lt;/SPAN&gt;&lt;SPAN class="language-bash"&gt;PROGRAMDATA%\Cyvera\Quarantine&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt;), but can I get it from there?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Would you hunt big files, which are executed by users?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;BR&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Rob&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Sep 2023 21:13:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantining-files-about-300-mb-hunting-big-files/m-p/557248#M5113</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-09-10T21:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: Quarantining files about 300 MB / Hunting big Files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantining-files-about-300-mb-hunting-big-files/m-p/557349#M5115</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;, thanks for contacting us in the Live Community.&lt;/P&gt;
&lt;P&gt;I'll do some checks and I'll be back with more information about retrieving files from quarantine (without restoring them).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is really hard to find a 300MB malware file, maybe a zipped one containing it. Is a size that is really hard to manage on any solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 13:51:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantining-files-about-300-mb-hunting-big-files/m-p/557349#M5115</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2023-09-11T13:51:00Z</dc:date>
    </item>
    <item>
      <title>Re: Quarantining files about 300 MB / Hunting big Files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantining-files-about-300-mb-hunting-big-files/m-p/557370#M5117</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;, I did some tests, and the files retrieved from the Qarantine folder, comes encrypted with a .qtn extension.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The option that comes to my mind, is:&lt;/P&gt;
&lt;P&gt;- Restore the file to the original location.&lt;/P&gt;
&lt;P&gt;- Retrieve it using the Action Center as you usually do.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Retrieve-Files-from-an-Endpoint" target="_self"&gt;max size of the files is 500MB&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please, le me know if it works for you, and mark the answer as the solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 17:07:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantining-files-about-300-mb-hunting-big-files/m-p/557370#M5117</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2023-09-11T17:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: Quarantining files about 300 MB / Hunting big Files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantining-files-about-300-mb-hunting-big-files/m-p/557415#M5119</link>
      <description>&lt;P&gt;Thank you so much for your attention to this question.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my mind I was able to get the file from quarantine. But I think in this case it is too big or the isolated endpoint didn't allow it. Maybe the client also wasn't online anymore.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, if I retreive files from quarantaine, the client needs to be online, right?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will try your suggestion, thank you!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 19:03:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantining-files-about-300-mb-hunting-big-files/m-p/557415#M5119</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-09-11T19:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: Quarantining files about 300 MB / Hunting big Files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantining-files-about-300-mb-hunting-big-files/m-p/557416#M5120</link>
      <description>&lt;P&gt;Yes, if you need the files at the moment, it needs to be online. If it is not, the task is hold as "Pending" until the client connects again with the console.&lt;/P&gt;
&lt;P&gt;I tried to retrieve files with the route&amp;nbsp;&lt;SPAN&gt;%PROGRAMDATA%\Cyvera\QuarantineV2\*.* and all came encrypted.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;JM&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 19:08:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantining-files-about-300-mb-hunting-big-files/m-p/557416#M5120</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2023-09-11T19:08:56Z</dc:date>
    </item>
  </channel>
</rss>

