<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Automatic deletion of files suspected/confirmed as malware in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-deletion-of-files-suspected-confirmed-as-malware/m-p/584496#M6554</link>
    <description>&lt;P&gt;where you found this scripts??&lt;/P&gt;</description>
    <pubDate>Mon, 22 Apr 2024 14:40:53 GMT</pubDate>
    <dc:creator>tlmarques</dc:creator>
    <dc:date>2024-04-22T14:40:53Z</dc:date>
    <item>
      <title>Automatic deletion of files suspected/confirmed as malware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-deletion-of-files-suspected-confirmed-as-malware/m-p/448949#M1263</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can the XDR auto delete files it has flagged, be it by local analysis or wildfire analysis? Or does it just block and quarantine files?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Nov 2021 09:06:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-deletion-of-files-suspected-confirmed-as-malware/m-p/448949#M1263</guid>
      <dc:creator>Daniel_Itenberg</dc:creator>
      <dc:date>2021-11-22T09:06:31Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic deletion of files suspected/confirmed as malware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-deletion-of-files-suspected-confirmed-as-malware/m-p/448983#M1266</link>
      <description>&lt;P&gt;looks like in the new v3.1 version you can do this:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV&gt;Permanently Delete Quarantined files&lt;/DIV&gt;&lt;DIV class=""&gt;(&lt;SPAN&gt;Requires a Cortex XDR agent 7.6 or a later release for Windows&lt;/SPAN&gt;)&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;To help you better manage malicious files which have been quarantined and avoid any potential mistake of restoring unwanted files, you can now permanently delete quarantined files on the endpoint from the File Quarantine Details page.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 22 Nov 2021 15:13:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-deletion-of-files-suspected-confirmed-as-malware/m-p/448983#M1266</guid>
      <dc:creator>P.Jacob</dc:creator>
      <dc:date>2021-11-22T15:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic deletion of files suspected/confirmed as malware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-deletion-of-files-suspected-confirmed-as-malware/m-p/540735#M4267</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aaminahassan_0-1683011031186.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49896i10C3ABEF6E14CD25/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="aaminahassan_0-1683011031186.png" alt="aaminahassan_0-1683011031186.png" /&gt;&lt;/span&gt;Hey! I want to ask more about it. whats the API call to delete file other than quarantine file API at end point.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 07:04:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-deletion-of-files-suspected-confirmed-as-malware/m-p/540735#M4267</guid>
      <dc:creator>aaminahassan</dc:creator>
      <dc:date>2023-05-02T07:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic deletion of files suspected/confirmed as malware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-deletion-of-files-suspected-confirmed-as-malware/m-p/540864#M4275</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/288862"&gt;@aaminahassan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding your use case above i.e. api call to delete file. You may run script using api to delete a file. There is a python script with name "delete_file" under Script library which you can locate at (Incident Response -&amp;gt; Response -&amp;gt; Action Center -&amp;gt; Agent Script Library). Using the api you may mention the file path of the file which needs to be deleted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Screenshot for reference:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PiyushKohli_0-1683090610663.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49920iC75B26E6268AC33E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PiyushKohli_0-1683090610663.png" alt="PiyushKohli_0-1683090610663.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;API Ref:&amp;nbsp;&lt;A href="https://cortex-panw.stoplight.io/docs/cortex-xdr/3675bfc1e315e-run-script" target="_blank"&gt;https://cortex-panw.stoplight.io/docs/cortex-xdr/3675bfc1e315e-run-script&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 05:12:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-deletion-of-files-suspected-confirmed-as-malware/m-p/540864#M4275</guid>
      <dc:creator>PiyushKohli</dc:creator>
      <dc:date>2023-05-03T05:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic deletion of files suspected/confirmed as malware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-deletion-of-files-suspected-confirmed-as-malware/m-p/540866#M4277</link>
      <description>Thanks for the prompt response.&lt;BR /&gt;Also please share the way out to whitelist USB using which API call? Under device control I can see only get_violations.  I can get_violations of device but don't know the exact parameters/API end point to whitelist the device.&lt;BR /&gt;</description>
      <pubDate>Wed, 03 May 2023 05:20:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-deletion-of-files-suspected-confirmed-as-malware/m-p/540866#M4277</guid>
      <dc:creator>aaminahassan</dc:creator>
      <dc:date>2023-05-03T05:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic deletion of files suspected/confirmed as malware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-deletion-of-files-suspected-confirmed-as-malware/m-p/584496#M6554</link>
      <description>&lt;P&gt;where you found this scripts??&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2024 14:40:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-deletion-of-files-suspected-confirmed-as-malware/m-p/584496#M6554</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-04-22T14:40:53Z</dc:date>
    </item>
  </channel>
</rss>

