<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Details regarding %PROGRAMDATA%\Cyvera\ folders in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/details-regarding-programdata-cyvera-folders/m-p/1225438#M8166</link>
    <description>&lt;P&gt;Interesting query I got was from a client running Microsoft defender alongside Cortex XDR. I already understand from another post:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-along-side-ms-defender-for-endpoint/td-p/1223498" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-along-side-ms-defender-for-endpoint/td-p/1223498&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not to have both active at the same time, either has to be either passive or disabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;His current situation is that Defender is flagging one of the recent files in&amp;nbsp;programdata/cyvera/prevention as spyware. As he asked what exactly this folder is, I realized that I am not sure what each folder inside the Cyvera section usage or function.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looking through administration guide was a futile effort as there was no details for folders.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone explain to me what each folder use is or at least for&amp;nbsp;programdata/cyvera/prevention?&lt;/P&gt;</description>
    <pubDate>Wed, 02 Apr 2025 08:29:39 GMT</pubDate>
    <dc:creator>MoKhaled</dc:creator>
    <dc:date>2025-04-02T08:29:39Z</dc:date>
    <item>
      <title>Details regarding %PROGRAMDATA%\Cyvera\ folders</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/details-regarding-programdata-cyvera-folders/m-p/1225438#M8166</link>
      <description>&lt;P&gt;Interesting query I got was from a client running Microsoft defender alongside Cortex XDR. I already understand from another post:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-along-side-ms-defender-for-endpoint/td-p/1223498" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-along-side-ms-defender-for-endpoint/td-p/1223498&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not to have both active at the same time, either has to be either passive or disabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;His current situation is that Defender is flagging one of the recent files in&amp;nbsp;programdata/cyvera/prevention as spyware. As he asked what exactly this folder is, I realized that I am not sure what each folder inside the Cyvera section usage or function.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looking through administration guide was a futile effort as there was no details for folders.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone explain to me what each folder use is or at least for&amp;nbsp;programdata/cyvera/prevention?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 08:29:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/details-regarding-programdata-cyvera-folders/m-p/1225438#M8166</guid>
      <dc:creator>MoKhaled</dc:creator>
      <dc:date>2025-04-02T08:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: Details regarding %PROGRAMDATA%\Cyvera\ folders</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/details-regarding-programdata-cyvera-folders/m-p/1225472#M8169</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/294635"&gt;@MoKhaled&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="CEG2AE8Q1-1595522554.142700-thread-list-Thread_1610462894.137700" class="c-virtual_list__item" tabindex="0" role="listitem" aria-setsize="-1" data-qa="virtual-list-item" data-item-key="1610462894.137700"&gt;
&lt;DIV class="c-message_kit__background c-message_kit__message c-message_kit__thread_message" role="presentation" data-qa="message_container" data-qa-unprocessed="false" data-qa-placeholder="false"&gt;
&lt;DIV class="c-message_kit__hover" role="document" aria-roledescription="message" data-qa-hover="true"&gt;
&lt;DIV class="c-message_kit__actions c-message_kit__actions--default"&gt;
&lt;DIV class="c-message_kit__gutter"&gt;
&lt;DIV class="c-message_kit__gutter__right" role="presentation" data-qa="message_content"&gt;
&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;DIV class="p-rich_text_section"&gt;This is where Prevention Data is stored locally, the file that you can request from the UI using (Retrieve Alert Data), aka the Prevention Dump.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="CEG2AE8Q1-1595522554.142700-thread-list-Thread_1610462935.137900" class="c-virtual_list__item" tabindex="-1" role="listitem" aria-setsize="-1" data-qa="virtual-list-item" data-item-key="1610462935.137900"&gt;
&lt;DIV class="c-message_kit__background c-message_kit__message c-message_kit__thread_message" role="presentation" data-qa="message_container" data-qa-unprocessed="false" data-qa-placeholder="false"&gt;
&lt;DIV class="c-message_kit__hover" role="document" aria-roledescription="message" data-qa-hover="true"&gt;
&lt;DIV class="c-message_kit__actions c-message_kit__actions--above"&gt;
&lt;DIV class="c-message_kit__gutter"&gt;
&lt;DIV class="c-message_kit__gutter__left" role="presentation"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="c-message_kit__gutter__right" role="presentation" data-qa="message_content"&gt;
&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;DIV class="p-rich_text_section"&gt;Recent Files are a component of this prevention dump, often containing files that were open at the time of the event, or libraries loaded into an offending/protected process and those sort of files.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="CEG2AE8Q1-1595522554.142700-thread-list-Thread_1610462988.138100" class="c-virtual_list__item" tabindex="-1" role="listitem" aria-setsize="-1" data-qa="virtual-list-item" data-item-key="1610462988.138100"&gt;
&lt;DIV class="c-message_kit__background c-message_kit__background--hovered c-message_kit__message c-message_kit__thread_message" role="presentation" data-qa="message_container" data-qa-unprocessed="false" data-qa-placeholder="false"&gt;
&lt;DIV class="c-message_kit__hover c-message_kit__hover--hovered" role="document" aria-roledescription="message" data-qa-hover="true"&gt;
&lt;DIV class="c-message_kit__actions c-message_kit__actions--above"&gt;
&lt;DIV class="c-message_kit__gutter"&gt;
&lt;DIV class="c-message_kit__gutter__left" role="presentation"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="c-message_kit__gutter__right" role="presentation" data-qa="message_content"&gt;
&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;DIV class="p-rich_text_section"&gt;You should exclude c:\programdata\Cyvera\* from all protection modules in Defender or it's going to cause issues one way or another.&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking like and&amp;nbsp; on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="CEG2AE8Q1-1595522554.142700-thread-list-Thread_input" class="c-virtual_list__item" tabindex="-1" role="listitem" aria-setsize="-1" data-qa="virtual-list-item" data-item-key="input"&gt;
&lt;DIV class="p-threads_footer__input_container p-threads_footer__input_container--sticky_composer" data-qa="reply_container"&gt;
&lt;DIV class="p-threads_footer__input p-message_input_unstyled p-message_input_unstyled--attachments-visible p-message_input_unstyled--dark" role="group" aria-label="composer"&gt;
&lt;DIV class="p-message_input__input_container_unstyled c-wysiwyg_container c-wysiwyg_container--theme_dark c-wysiwyg_container--with_footer c-wysiwyg_container--theme_dark_bordered c-basic_container c-basic_container--size_medium" data-max-lines="16"&gt;
&lt;DIV class="c-basic_container__body"&gt;
&lt;DIV class="c-wysiwyg_container__formatting" role="toolbar" aria-orientation="horizontal" aria-label="Formatting" data-qa="wysiwyg-container_formatting-enabled"&gt;
&lt;DIV class="p-texty_sticky_formatting_bar"&gt;
&lt;DIV&gt;
&lt;DIV class="p-composer__body p-composer__body--visible p-composer__body--unstyled"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 02 Apr 2025 15:56:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/details-regarding-programdata-cyvera-folders/m-p/1225472#M8169</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2025-04-02T15:56:39Z</dc:date>
    </item>
  </channel>
</rss>

