<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to retrieve an incident related file in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-retrieve-an-incident-related-file/m-p/571210#M5820</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I want to download an incident related files in Cortex XDR, but one of them is already quarantined so when I try to retrieve it nothing happens since it's not in the original location anymore. Is there any way to download it without restoring it from quarantine?&lt;/P&gt;</description>
    <pubDate>Fri, 29 Dec 2023 11:03:20 GMT</pubDate>
    <dc:creator>Arman_Zaheri</dc:creator>
    <dc:date>2023-12-29T11:03:20Z</dc:date>
    <item>
      <title>How to retrieve an incident related file</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-retrieve-an-incident-related-file/m-p/571210#M5820</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I want to download an incident related files in Cortex XDR, but one of them is already quarantined so when I try to retrieve it nothing happens since it's not in the original location anymore. Is there any way to download it without restoring it from quarantine?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2023 11:03:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-retrieve-an-incident-related-file/m-p/571210#M5820</guid>
      <dc:creator>Arman_Zaheri</dc:creator>
      <dc:date>2023-12-29T11:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to retrieve an incident related file</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-retrieve-an-incident-related-file/m-p/571620#M5834</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/922167235"&gt;@Arman_Zaheri&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When the agent&amp;nbsp;&lt;SPAN class="proto-highlight"&gt;quarantine&lt;/SPAN&gt;s malware, it moves the file from the location on a local or removable drive to a local&amp;nbsp;&lt;SPAN class="proto-highlight"&gt;quarantine&lt;/SPAN&gt;&amp;nbsp;folder (&lt;/SPAN&gt;&lt;CODE class="filename hljs language-shell"&gt;&lt;SPAN class="hljs-meta prompt_"&gt;%&lt;/SPAN&gt;&lt;SPAN class="language-bash"&gt;PROGRAMDATA%\Cyvera\Quarantine&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt;) where it isolates the file. This prevents the file from attempting to run again from the same path or causing any harm to your endpoints. Durning this process the extension of the file is also changed to ".qtn". Accessing this file in this format will not help with analysis in a sandbox environment. Hence if you want to download a file from quarantine folder you need to restore it first.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please refer below link for more details.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-Quarantined-Files" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-Quarantined-Files&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please click&amp;nbsp;&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;&amp;nbsp;to acknowledge that the answer to your question has been provided.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 15:27:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-retrieve-an-incident-related-file/m-p/571620#M5834</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2024-01-03T15:27:26Z</dc:date>
    </item>
  </channel>
</rss>

