<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Scan endpoint error in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-endpoint-error/m-p/575865#M6020</link>
    <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope you are doing well, and thank you for reaching out to our Live Community. From the above query I believe that you are trying to see how to configure the end users to initiate a full scan from the Cortex XDR interface locally on endpoint.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please note that a full scan can only be initiated from Cortex XDR portal by navigating to&amp;nbsp;&lt;SPAN class="guimenu"&gt;Incident Response&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;→&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guisubmenu"&gt;Response&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;→&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guimenuitem"&gt;Action Center&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="guimenuitem"&gt;Please find the document provided below for further details, thank you:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Scan-an-Endpoint-for-Malware" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Scan-an-Endpoint-for-Malware&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="guimenuitem"&gt;And for the configuration you have provided in the second screenshot, this configuration is used to allow the end user to initiate a right click scan on a file or folder as seen in the screenshot provided below, thank you:&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="abdrahman_0-1706976458862.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57336i1A57F7A84BE2D666/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="abdrahman_0-1706976458862.png" alt="abdrahman_0-1706976458862.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="guimenuitem"&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you. &lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 03 Feb 2024 16:09:20 GMT</pubDate>
    <dc:creator>abdrahman</dc:creator>
    <dc:date>2024-02-03T16:09:20Z</dc:date>
    <item>
      <title>Scan endpoint error</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-endpoint-error/m-p/575537#M6018</link>
      <description>&lt;P&gt;Hi, I need help, I have &lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;policy to allow scans on the endpoint, however users are unable to start the scans, the option does not appear&lt;/P&gt;
&lt;P&gt;I can only scan, with cmd as administrator (cytool scan start) , in the GUI I can't even do it as administrator:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tlmarques_0-1706887670317.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57059i40F9987664233684/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="tlmarques_0-1706887670317.png" alt="tlmarques_0-1706887670317.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;my configuration:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tlmarques_1-1706887790216.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57060i17790765B317A953/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="tlmarques_1-1706887790216.png" alt="tlmarques_1-1706887790216.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 15:30:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-endpoint-error/m-p/575537#M6018</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-02-02T15:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: Scan endpoint error</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-endpoint-error/m-p/575865#M6020</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope you are doing well, and thank you for reaching out to our Live Community. From the above query I believe that you are trying to see how to configure the end users to initiate a full scan from the Cortex XDR interface locally on endpoint.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please note that a full scan can only be initiated from Cortex XDR portal by navigating to&amp;nbsp;&lt;SPAN class="guimenu"&gt;Incident Response&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;→&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guisubmenu"&gt;Response&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;→&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guimenuitem"&gt;Action Center&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="guimenuitem"&gt;Please find the document provided below for further details, thank you:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Scan-an-Endpoint-for-Malware" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Scan-an-Endpoint-for-Malware&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="guimenuitem"&gt;And for the configuration you have provided in the second screenshot, this configuration is used to allow the end user to initiate a right click scan on a file or folder as seen in the screenshot provided below, thank you:&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="abdrahman_0-1706976458862.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57336i1A57F7A84BE2D666/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="abdrahman_0-1706976458862.png" alt="abdrahman_0-1706976458862.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="guimenuitem"&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you. &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Feb 2024 16:09:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-endpoint-error/m-p/575865#M6020</guid>
      <dc:creator>abdrahman</dc:creator>
      <dc:date>2024-02-03T16:09:20Z</dc:date>
    </item>
    <item>
      <title>Re: Scan endpoint error</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-endpoint-error/m-p/577057#M6057</link>
      <description>&lt;P&gt;we've that configuration enabled....the problem is the agent...i open a case with support and we found the problem.&lt;BR /&gt;&lt;BR /&gt;For future, if someone have the same problem, check that:&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;OS version:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;In the case of Windows 11, it will show clicking the “Show More Options” in the context menu.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Registry:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;This is a registry key related to “Show More Options” in the context menu.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Please check if they are in the registry key.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Cortex.XDR.Scan&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- HKEY_CLASSES_ROOT\CLSID\{44303AF8-6F09-4803-8639-9247339BE42D}&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\Cortex.XDR.Scan&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\Cortex.XDR.Scan&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If registry keys are missing, please re-install the agent.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2024 19:58:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/scan-endpoint-error/m-p/577057#M6057</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-02-12T19:58:09Z</dc:date>
    </item>
  </channel>
</rss>

