<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR to take the cleanest snapshot of windows for rollback. in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-to-take-the-cleanest-snapshot-of-windows-for-rollback/m-p/564493#M5479</link>
    <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/315146"&gt;@Jim_Gabales&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out to the Live Community. We do have a feature in Cortex XDR which assist in backup management where we can enable or disable the automatic backup on Windows using VSS.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can find these settings in policy management&amp;gt; Agent settings&amp;gt; backup management. However, as far as I know we cannot take a backup of the endpoints on the Cortex XDR so that we can restore using it. We can only manage the enabling or disabling of the backup from the Cortex XDR. Thank you.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.&lt;/P&gt;</description>
    <pubDate>Mon, 06 Nov 2023 10:34:30 GMT</pubDate>
    <dc:creator>abdrahman</dc:creator>
    <dc:date>2023-11-06T10:34:30Z</dc:date>
    <item>
      <title>Cortex XDR to take the cleanest snapshot of windows for rollback.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-to-take-the-cleanest-snapshot-of-windows-for-rollback/m-p/564411#M5477</link>
      <description>&lt;P&gt;Hi LIVEcommunity,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way for Cortex XDR to take the cleanest snapshot of windows so there is a point where we can rollback the endpoint after an attack?&lt;/P&gt;
&lt;P&gt;Windows has a feature called Volume Shadow Copy Service (VSS) but can Cortex XDR use this after a ransomware attack? What if the VSS is corrupted, how can Cortex XDR protect the VSS and rollback to the cleanest state of the endpoint?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are trying to compete with other product that has a feature like this, but I cannot find documentation stating how can Cortex XDR accomplish this task.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope experts in this community can guide us. Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Jim&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Nov 2023 05:40:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-to-take-the-cleanest-snapshot-of-windows-for-rollback/m-p/564411#M5477</guid>
      <dc:creator>Jim_Gabales</dc:creator>
      <dc:date>2023-11-05T05:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR to take the cleanest snapshot of windows for rollback.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-to-take-the-cleanest-snapshot-of-windows-for-rollback/m-p/564493#M5479</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/315146"&gt;@Jim_Gabales&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out to the Live Community. We do have a feature in Cortex XDR which assist in backup management where we can enable or disable the automatic backup on Windows using VSS.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can find these settings in policy management&amp;gt; Agent settings&amp;gt; backup management. However, as far as I know we cannot take a backup of the endpoints on the Cortex XDR so that we can restore using it. We can only manage the enabling or disabling of the backup from the Cortex XDR. Thank you.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 10:34:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-to-take-the-cleanest-snapshot-of-windows-for-rollback/m-p/564493#M5479</guid>
      <dc:creator>abdrahman</dc:creator>
      <dc:date>2023-11-06T10:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR to take the cleanest snapshot of windows for rollback.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-to-take-the-cleanest-snapshot-of-windows-for-rollback/m-p/565840#M5543</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/290451"&gt;@abdrahman&lt;/a&gt; , I was looking at this new feature "Backup Management" and you explained that it works with the VSS.&lt;BR /&gt;However, I listed the VSS writers and I do not see a Writer "Cortex XDR".&lt;/P&gt;
&lt;P&gt;Does it mean that the shadow copy driven by the agent has not been write ?&lt;/P&gt;
&lt;P&gt;I checked the Agent Settings profile and I can see that the option is Enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can I check on the endpoint that the backup has been made by the agent ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 15:08:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-to-take-the-cleanest-snapshot-of-windows-for-rollback/m-p/565840#M5543</guid>
      <dc:creator>benjamin_nogue</dc:creator>
      <dc:date>2023-11-15T15:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR to take the cleanest snapshot of windows for rollback.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-to-take-the-cleanest-snapshot-of-windows-for-rollback/m-p/565849#M5545</link>
      <description>&lt;P&gt;I see, but can we automate the part of restoring it using the enabled shadowcopy? we have a remediation suggestion feature "restoring files", right? Will it trigger the shadow copy to be restored?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 15:48:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-to-take-the-cleanest-snapshot-of-windows-for-rollback/m-p/565849#M5545</guid>
      <dc:creator>Jim_Gabales</dc:creator>
      <dc:date>2023-11-15T15:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR to take the cleanest snapshot of windows for rollback.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-to-take-the-cleanest-snapshot-of-windows-for-rollback/m-p/1238660#M8749</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/182353"&gt;@benjamin_nogue&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/315146"&gt;@Jim_Gabales&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Hello experts,&amp;nbsp;&lt;BR /&gt;Sorry for bothering you, this is an old thread, just came accros the same queries as you.&lt;/P&gt;
&lt;P&gt;Did you find out the answer ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it seems XDR will just "enabled" the VSS on the endpoints which relies on the default Schedule of the VSS volumn, XDR (is not a backup software) will not fire an VSS snapshot backup, i guess. please correct me if i'm wrong.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 24 Sep 2025 12:17:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-to-take-the-cleanest-snapshot-of-windows-for-rollback/m-p/1238660#M8749</guid>
      <dc:creator>SeanDeHarris</dc:creator>
      <dc:date>2025-09-24T12:17:18Z</dc:date>
    </item>
  </channel>
</rss>

