<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File retrieval in user context in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-retrieval-in-user-context/m-p/1221796#M7953</link>
    <description>&lt;P&gt;Thanks for your response. Two questions regarding live terminal:&lt;/P&gt;
&lt;P&gt;1. I checked live terminal before, it's also running under SYSTEM. But I'll check this again to make sure.&lt;/P&gt;
&lt;P&gt;2. Assuming this statement is true, how can we automate this retrieval? The endpoint might not be online at the moment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR,&lt;/P&gt;</description>
    <pubDate>Mon, 24 Feb 2025 18:37:19 GMT</pubDate>
    <dc:creator>Arman_Zaheri</dc:creator>
    <dc:date>2025-02-24T18:37:19Z</dc:date>
    <item>
      <title>File retrieval in user context</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-retrieval-in-user-context/m-p/1221775#M7951</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Is it possible to retrieve a file which is only accessible in user's context? I have an incident which user opened a file from a network mapped drive. That drive might not be accessible by anyone except for the user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which user context is used when we initiate File retrieval via:&lt;/P&gt;
&lt;P&gt;1. Cortex console or an agent script&lt;/P&gt;
&lt;P&gt;2. Live terminal&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you very much&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 15:39:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-retrieval-in-user-context/m-p/1221775#M7951</guid>
      <dc:creator>Arman_Zaheri</dc:creator>
      <dc:date>2025-02-24T15:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: File retrieval in user context</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-retrieval-in-user-context/m-p/1221795#M7952</link>
      <description>&lt;P&gt;Yes, retrieving a file that is only accessible in the &lt;STRONG data-start="54" data-end="72"&gt;user’s context&lt;/STRONG&gt; (such as a network-mapped drive) using &lt;STRONG data-start="112" data-end="126"&gt;Cortex XDR&lt;/STRONG&gt; can be challenging because the &lt;STRONG data-start="158" data-end="186"&gt;XDR agent runs as SYSTEM&lt;/STRONG&gt;, which may not have access to the user’s mapped drives. However, there are &lt;STRONG data-start="262" data-end="277"&gt;workarounds&lt;/STRONG&gt; to retrieve the file:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Use Live Terminal (Best for Interactive Access)&lt;BR /&gt;If the user is online, the best method is to use Live Terminal to access the user's session and retrieve the file.&lt;/P&gt;
&lt;P&gt;Steps:&lt;/P&gt;
&lt;P&gt;Go to Cortex XDR → Response → Live Terminal&lt;BR /&gt;Select the affected endpoint.&lt;/P&gt;
&lt;P&gt;Run the following PowerShell command to check the user’s network drives:&lt;BR /&gt;powershell&lt;BR /&gt;Get-PSDrive -PSProvider FileSystem&lt;/P&gt;
&lt;P&gt;This will list the user’s mapped network drives (e.g., Z:\).&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Copy the file from the network drive to a local path that XDR can access:&lt;BR /&gt;powershell&lt;BR /&gt;Copy-Item "Z:\path\to\file.txt" -Destination "C:\Temp\file.txt"&lt;BR /&gt;Use File Fetch (see Method 2) to retrieve the file from C:\Temp&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 18:28:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-retrieval-in-user-context/m-p/1221795#M7952</guid>
      <dc:creator>Mudhireddy</dc:creator>
      <dc:date>2025-02-24T18:28:13Z</dc:date>
    </item>
    <item>
      <title>Re: File retrieval in user context</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-retrieval-in-user-context/m-p/1221796#M7953</link>
      <description>&lt;P&gt;Thanks for your response. Two questions regarding live terminal:&lt;/P&gt;
&lt;P&gt;1. I checked live terminal before, it's also running under SYSTEM. But I'll check this again to make sure.&lt;/P&gt;
&lt;P&gt;2. Assuming this statement is true, how can we automate this retrieval? The endpoint might not be online at the moment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR,&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 18:37:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-retrieval-in-user-context/m-p/1221796#M7953</guid>
      <dc:creator>Arman_Zaheri</dc:creator>
      <dc:date>2025-02-24T18:37:19Z</dc:date>
    </item>
  </channel>
</rss>

