<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mac offline scan in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/mac-offline-scan/m-p/564596#M5488</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/327550"&gt;@EricBjurstrom&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out to Palo Alto Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In case your endpoint is compromised then you can first isolate the compromise endpoint.&amp;nbsp;&lt;SPAN&gt;When you isolate an endpoint, you halt all network access on the endpoint except for traffic to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="phrase"&gt;Cortex XDR&lt;/SPAN&gt;&lt;SPAN&gt;. This can prevent a compromised endpoint from communicating with other endpoints thereby reducing an attacker’s mobility on your network.&lt;/SPAN&gt; please refer the document below for more information:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Isolate-an-Endpoint" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Isolate-an-Endpoint&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After isolating the endpoint you can run the malware scan on a compromised endpoint, please refer the document below for more information about malware scan:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Scan-an-Endpoint-for-Malware" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Scan-an-Endpoint-for-Malware&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please mark the response as "Accept as Solution"&lt;/P&gt;</description>
    <pubDate>Tue, 07 Nov 2023 06:43:15 GMT</pubDate>
    <dc:creator>dbahuguna</dc:creator>
    <dc:date>2023-11-07T06:43:15Z</dc:date>
    <item>
      <title>Mac offline scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/mac-offline-scan/m-p/564540#M5485</link>
      <description>&lt;P&gt;We have a mac that we suspect may be compromised.&amp;nbsp; We would like to run a scan with the device offline and not connected to our network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How would we go about doing this?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 18:11:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/mac-offline-scan/m-p/564540#M5485</guid>
      <dc:creator>EricBjurstrom</dc:creator>
      <dc:date>2023-11-06T18:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: Mac offline scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/mac-offline-scan/m-p/564596#M5488</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/327550"&gt;@EricBjurstrom&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out to Palo Alto Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In case your endpoint is compromised then you can first isolate the compromise endpoint.&amp;nbsp;&lt;SPAN&gt;When you isolate an endpoint, you halt all network access on the endpoint except for traffic to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="phrase"&gt;Cortex XDR&lt;/SPAN&gt;&lt;SPAN&gt;. This can prevent a compromised endpoint from communicating with other endpoints thereby reducing an attacker’s mobility on your network.&lt;/SPAN&gt; please refer the document below for more information:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Isolate-an-Endpoint" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Isolate-an-Endpoint&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After isolating the endpoint you can run the malware scan on a compromised endpoint, please refer the document below for more information about malware scan:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Scan-an-Endpoint-for-Malware" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Scan-an-Endpoint-for-Malware&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please mark the response as "Accept as Solution"&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 06:43:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/mac-offline-scan/m-p/564596#M5488</guid>
      <dc:creator>dbahuguna</dc:creator>
      <dc:date>2023-11-07T06:43:15Z</dc:date>
    </item>
  </channel>
</rss>

