<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tracking Corrupt Cortex XDR Agents in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/405407#M717</link>
    <description>&lt;P&gt;Your reply could also be quite helpful,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/171418"&gt;@Alexandre_Jodoin&lt;/a&gt;,&amp;nbsp;thanks for sharing your solution!&lt;/P&gt;&lt;P&gt;You guys are giving me some interesting things to look at.&lt;/P&gt;</description>
    <pubDate>Fri, 07 May 2021 06:24:47 GMT</pubDate>
    <dc:creator>btenberge</dc:creator>
    <dc:date>2021-05-07T06:24:47Z</dc:date>
    <item>
      <title>Tracking Corrupt Cortex XDR Agents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/393897#M644</link>
      <description>&lt;P&gt;I am looking for any input on how other customers are handling situations where:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. The agent is installed on a host and says it is checking in, but it does not appear in the Cortex XDR Console&lt;/P&gt;&lt;P&gt;2. The agent is corrupt and has stopped reporting back (due to a failed upgrade or otherwise)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I didn't know if anyone has any unique solutions for these situations. From a corrupt agent standpoint, it would be nice to have a Tenable plugin to report back the current signature versions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 15:01:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/393897#M644</guid>
      <dc:creator>thenetworksfine</dc:creator>
      <dc:date>2021-03-25T15:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: Tracking Corrupt Cortex XDR Agents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/394039#M646</link>
      <description>&lt;P&gt;I can't say that I saw 1) but 2) sounds too familliar.&lt;/P&gt;&lt;P&gt;I estimate that we have, at any given time, about 3-5% of the agents in that situation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically, I have a script that will re-create/re-enable the runtimes, as I found this is mostly the case with corrupted installation.&lt;/P&gt;&lt;P&gt;The cyserver services won't start as one of the dependencies is borked. So the script tries to fix them all.&lt;/P&gt;&lt;P&gt;This works in 20% of the corrupted agent cases.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the others it is an issue with the file system filter. trying to reload it using fltmc fails with a "file not found" error and I haven't been able to find a solution for those, so it is xdrcleaner, reboot, xdrcleaner, re-install.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But 3-5% of 18k agents is a lot to manually fix month after month.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 18:38:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/394039#M646</guid>
      <dc:creator>Alexandre_Jodoin</dc:creator>
      <dc:date>2021-03-25T18:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: Tracking Corrupt Cortex XDR Agents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/394928#M648</link>
      <description>&lt;P&gt;I'm sorry I don't have an answer to your question either, but I think this is a good subject because I'm having the same "revelations" lately.&lt;/P&gt;&lt;P&gt;I have encountered some agents in our environment that appear to be working (they appear online and up-to-date), but half the files are missing in the installation folder, only cyserver.exe is running and upgrade attempts fail all the time.&lt;/P&gt;&lt;P&gt;These specific instances do make it seem like everything is fine and dandy, while it's not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently trying to figure out a way to find these half-, or non-operational agents, myself, but I have nothing yet.&lt;/P&gt;&lt;P&gt;I'm sure we're not the only ones dealing with this problem, so I'm hoping that there are some people that have already found a working solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 12:37:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/394928#M648</guid>
      <dc:creator>btenberge</dc:creator>
      <dc:date>2021-03-30T12:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: Tracking Corrupt Cortex XDR Agents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/397292#M655</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/171418"&gt;@Alexandre_Jodoin&lt;/a&gt;&amp;nbsp;We are working through a wide range of hosts with support to get to the bottom of this situation. One of the commonalities ended up being deleted Installation Packages under Cortex XDR Administrative Console &amp;gt;&amp;gt; Endpoints &amp;gt;&amp;gt; Endpoint Management &amp;gt;&amp;gt; Agent Installations. I'm not saying this is the case for you but we did not know that someone was cleaning up these packages and wouldn't have though it would put the agent dead in the water. The agent is not smart enough to go out and get the latest version from the console if the previously sent version no longer exists.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A helpful command that we used is below. This prevented us from having to reinstall the agent in a number of situations.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;From an administrative command prompt&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;C:\Program Files\Palo Alto Networks\Traps\cytool.exe reconnect force &amp;lt;ID&amp;gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Where &amp;lt;ID&amp;gt; = the agent ID that corresponds to an agent installation package name with the installed version of the agent. You can show the id field within&amp;nbsp;Cortex XDR Administrative Console &amp;gt;&amp;gt; Endpoints &amp;gt;&amp;gt; Endpoint Management &amp;gt;&amp;gt; Agent Installations.&lt;/LI&gt;&lt;LI&gt;The agent administrative password is then required&lt;/LI&gt;&lt;LI&gt;Click Check In Now on the agent console&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;We are working through some other scenarios so I will update this post accordingly in hopes to help out some other customers in our situation.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Apr 2021 18:04:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/397292#M655</guid>
      <dc:creator>thenetworksfine</dc:creator>
      <dc:date>2021-04-12T18:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: Tracking Corrupt Cortex XDR Agents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/397293#M656</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/19436"&gt;@btenberge&lt;/a&gt;&amp;nbsp;See my reply to&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/171418"&gt;@Alexandre_Jodoin&lt;/a&gt;&amp;nbsp;below.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Apr 2021 18:04:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/397293#M656</guid>
      <dc:creator>thenetworksfine</dc:creator>
      <dc:date>2021-04-12T18:04:46Z</dc:date>
    </item>
    <item>
      <title>Re: Tracking Corrupt Cortex XDR Agents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/397325#M657</link>
      <description>&lt;P&gt;Thank you for this, it is an option I wasn't aware of, and I will give this a try on a few agents to see.&lt;/P&gt;&lt;P&gt;When trying to delete and installation package from the console it DOES give a warning:"&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;This will prevent new agents using the package, including VDI, from registering.&lt;/SPAN&gt;&lt;/FONT&gt;"&lt;/P&gt;&lt;P&gt;So I've never deleted a single package. Not sure if that will be an issue 5 years from now...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our main issue has to do with the file system filter driver/main cyserver service.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's a bacth file I created to help with service issues. However this does NOT fix the&amp;nbsp;cyvrfsfd filter issue we are seing.&lt;/P&gt;&lt;P&gt;NOT the silver bullet but might help to re-enable some agents...&lt;/P&gt;&lt;P&gt;-----------------------&lt;/P&gt;&lt;P&gt;@echo on&lt;/P&gt;&lt;P&gt;REM Stop the runtimes&lt;BR /&gt;echo PasswordHERE!!!|"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" runtime stop&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;REM remove autoprotection&lt;BR /&gt;echo PasswordHERE!!!|"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" protect disable&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;sc create cyvrfsfd binpath= "C:\Program Files\Palo Alto Networks\Traps\cyvrfsfd.sys" type= filesys start= system error= normal group= "FSFilter Anti-Virus" tag= yes displayname= cyvrfsfd depend= FltMgr || sc config cyvrfsfd binpath= "C:\Program Files\Palo Alto Networks\Traps\cyvrfsfd.sys" type= filesys start= system error= normal group= "FSFilter Anti-Virus" tag= yes displayname= cyvrfsfd depend= FltMgr&lt;BR /&gt;sc create cyverak type= KERNEL start= system error= normal binpath= "C:\Program Files\Palo Alto Networks\Traps\cyverak.sys" tag= no displayname= cyverak || sc config cyverak type= KERNEL start= system error= normal binpath= "C:\Program Files\Palo Alto Networks\Traps\cyverak.sys" tag= no displayname= cyverak&lt;BR /&gt;sc create cyvrmtgn type= KERNEL start= system error= normal binpath= "C:\Program Files\Palo Alto Networks\Traps\cyvrmtgn.sys" tag= no displayname= cyvrmtgn || sc config cyvrmtgn type= KERNEL start= system error= normal binpath= "C:\Program Files\Palo Alto Networks\Traps\cyvrmtgn.sys" tag= no displayname= cyvrmtgn&lt;BR /&gt;sc create tedrdrv type= filesys start= system error= normal binpath= "C:\Program Files\Palo Alto Networks\Traps\tedrdrv.sys" group= "FSFilter Activity Monitor" tag= yes displayname= tedrdrv depend= FltMgr || sc config tedrdrv type= filesys start= system error= normal binpath= "C:\Program Files\Palo Alto Networks\Traps\tedrdrv.sys" group= "FSFilter Activity Monitor" tag= yes displayname= tedrdrv depend= FltMgr&lt;BR /&gt;sc create cyserver type= own start= auto error= normal binpath= "C:\Program Files\Palo Alto Networks\Traps\cyserver.exe" tag= no displayname= "Cortex XDR" depend= Cyvrmtgn/Cyverak/Cyvrfsfd/EventLog/CryptSvc/TEdrDrv || sc config cyserver type= own start= auto error= normal binpath= "C:\Program Files\Palo Alto Networks\Traps\cyserver.exe" tag= no displayname= "Cortex XDR" depend= Cyvrmtgn/Cyverak/Cyvrfsfd/EventLog/CryptSvc/TEdrDrv&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;REM Oh CRAP! sc start ftlmgr -&amp;gt; The specified service does not exist as an installed service&lt;BR /&gt;sc config FltMgr type= filesys start= boot error= critical binpath= "C:\Windows\system32\drivers\fltmgr.sys" group= "FSFilter Infrastructure" tag= yes displayname= FltMgr || sc create FltMgr type= filesys start= boot error= critical binpath= "C:\Windows\system32\drivers\fltmgr.sys" group= "FSFilter Infrastructure" tag= yes displayname= FltMgr&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;REM Set the services/drivers/filters to auto start, not required since we did it already.&lt;BR /&gt;REM sc config cyserver start= auto &amp;amp;&amp;amp; sc config cyverak start=system &amp;amp;&amp;amp; sc config cyvrmtgn start= system &amp;amp;&amp;amp; sc config cyvrfsfd start= system &amp;amp;&amp;amp; sc config tedrdrv start= system&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;REM Enable autoprotection&lt;BR /&gt;echo PasswordHERE!!!|"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" protect enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;REM start the services/drivers/filters. Use one or the other. Or both.&lt;BR /&gt;sc start cyverak &amp;amp; sc start cyvrmtgn &amp;amp; sc start cyvrfsfd &amp;amp; sc start tedrdrv &amp;amp; sc start cyserver&lt;BR /&gt;REM "C:\Program Files\Palo Alto Networks\Traps\cytool.exe" runtime start&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;REM Try reconnecting if communication with server has been disabled&lt;BR /&gt;echo PasswordHERE!!!|"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" reconnect&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;REM Update Cortex XDR from server&lt;BR /&gt;"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" checkin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;REM Check Protection determined by policy&lt;BR /&gt;REM echo PasswordHERE!!!|"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" protect policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;REM Query product components running state&lt;BR /&gt;"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" runtime query&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;REM Altitude and volumes for the filter can be found by issuing this command on an agent in working order:&lt;/P&gt;&lt;P&gt;REM&amp;nbsp;fltmc instances&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;REM Filtre Nom du volume Altitude Nom de l’instance Cadre SprtFtrs VlStatus&lt;BR /&gt;REM -------------------- ------------------------------------- ------------ ---------------------- ----- -------- --------&lt;BR /&gt;REM cyvrfsfd 321234 Cyvera FSFD 0 00000007&lt;BR /&gt;REM cyvrfsfd C: 321234 Cyvera FSFD 0 00000007&lt;BR /&gt;REM cyvrfsfd 321234 Cyvera FSFD 0 00000007&lt;BR /&gt;REM cyvrfsfd \Device\Mup 321234 Cyvera FSFD 0 00000007&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;REM Saw this one once. Not bother fixing it for all. But here's the info if required.&lt;/P&gt;&lt;P&gt;REM SERVICE_NAME: telam&lt;BR /&gt;REM TYPE : 1 KERNEL_DRIVER&lt;BR /&gt;REM START_TYPE : 0 BOOT_START&lt;BR /&gt;REM ERROR_CONTROL : 1 NORMAL&lt;BR /&gt;REM BINARY_PATH_NAME : \SystemRoot\system32\drivers\telam.sys&lt;BR /&gt;REM LOAD_ORDER_GROUP : early-launch&lt;BR /&gt;REM TAG : 0&lt;BR /&gt;REM DISPLAY_NAME : telam&lt;BR /&gt;REM DEPENDENCIES :&lt;BR /&gt;REM SERVICE_START_NAME :&lt;/P&gt;&lt;P&gt;REM sc create telam binpath= "C:\Windows\system32\drivers\telam.sys" type= kernel start= boot error= normal group= "early-launch" tag= no displayname= telam&lt;/P&gt;</description>
      <pubDate>Mon, 12 Apr 2021 18:57:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/397325#M657</guid>
      <dc:creator>Alexandre_Jodoin</dc:creator>
      <dc:date>2021-04-12T18:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: Tracking Corrupt Cortex XDR Agents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/405406#M716</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/128741"&gt;@thenetworksfine&lt;/a&gt;&amp;nbsp;Thanks for your reply!&lt;/P&gt;&lt;P&gt;I haven't ever removed any old installation packages, I think, but it's worth checking out for sure.&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2021 06:22:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/405406#M716</guid>
      <dc:creator>btenberge</dc:creator>
      <dc:date>2021-05-07T06:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: Tracking Corrupt Cortex XDR Agents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/405407#M717</link>
      <description>&lt;P&gt;Your reply could also be quite helpful,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/171418"&gt;@Alexandre_Jodoin&lt;/a&gt;,&amp;nbsp;thanks for sharing your solution!&lt;/P&gt;&lt;P&gt;You guys are giving me some interesting things to look at.&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2021 06:24:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/405407#M717</guid>
      <dc:creator>btenberge</dc:creator>
      <dc:date>2021-05-07T06:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: Tracking Corrupt Cortex XDR Agents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/450421#M1308</link>
      <description>&lt;P&gt;Does anyone have an update to this issue, it seems to exist around version upgrades that a small percent will stop responding.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 15:54:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/450421#M1308</guid>
      <dc:creator>MParker4</dc:creator>
      <dc:date>2021-11-30T15:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: Tracking Corrupt Cortex XDR Agents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/450551#M1310</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/164362"&gt;@MParker4&lt;/a&gt;&amp;nbsp;, this seems like an issue with the agent. Please generate a support file for a few affected endpoints, create a Support Ticket, and upload the support files for the PANW TAC Engineers to investigate.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 02:18:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/450551#M1310</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2021-12-01T02:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: Tracking Corrupt Cortex XDR Agents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/450681#M1311</link>
      <description>&lt;P&gt;Hopefully this will save you from months of log collection. There is a known bug with agent upgrades prior to the versions below. Unfortunately all support reps are not aware. See the comment below from support that we received once the right people got involved with our ticket.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Moving forward from 7.4.1-&amp;gt;7.4.2 and onward you should not run into this issue"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What version are you noticing issues with?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 16:19:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/tracking-corrupt-cortex-xdr-agents/m-p/450681#M1311</guid>
      <dc:creator>thenetworksfine</dc:creator>
      <dc:date>2021-12-01T16:19:12Z</dc:date>
    </item>
  </channel>
</rss>

