<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR file quarantine in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-file-quarantine/m-p/1232972#M8506</link>
    <description>&lt;P&gt;Hi Oasha,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Answering your questions:&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;You can use the feature search and destroy files at the Action Center. If you search and destroy by hash, that file will be deleted no matter the path where it is located and even if there are more than one copy of that file at the same endpoint, it will delete it. The agents make a scan once they are installed and keep a database of files with hashes, paths etc.. so every Agent will know where to find that file if it exists.&lt;BR /&gt;Please you can use the doc for more info:&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Search-and-destroy-malicious-files" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Search-and-destroy-malicious-files&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Related to delete the malicious files without confirmation by the user: At profiles configuration, and specifically Malware Profiles, you will see a different area of configuration options for every malware protection module. There you can choose block mode in one option and in another you can choose quarantine enabled or disabled. If you use block mode and quarantine disabled, the malicious files will be blocked but not deleted, so you need to use the File Search and Destroy feature mentioned on the previous answer.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luis&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Jul 2025 14:52:01 GMT</pubDate>
    <dc:creator>eluis</dc:creator>
    <dc:date>2025-07-01T14:52:01Z</dc:date>
    <item>
      <title>Cortex XDR file quarantine</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-file-quarantine/m-p/1232956#M8504</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i have two general questions,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1-can i delete a file from multiple endpoints but with different paths from the action centre?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2- i understand that cortex can quarantine a malicious file but is there an option to delete it without my interference?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2025 08:21:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-file-quarantine/m-p/1232956#M8504</guid>
      <dc:creator>O.Asha</dc:creator>
      <dc:date>2025-07-01T08:21:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR file quarantine</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-file-quarantine/m-p/1232972#M8506</link>
      <description>&lt;P&gt;Hi Oasha,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Answering your questions:&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;You can use the feature search and destroy files at the Action Center. If you search and destroy by hash, that file will be deleted no matter the path where it is located and even if there are more than one copy of that file at the same endpoint, it will delete it. The agents make a scan once they are installed and keep a database of files with hashes, paths etc.. so every Agent will know where to find that file if it exists.&lt;BR /&gt;Please you can use the doc for more info:&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Search-and-destroy-malicious-files" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Search-and-destroy-malicious-files&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Related to delete the malicious files without confirmation by the user: At profiles configuration, and specifically Malware Profiles, you will see a different area of configuration options for every malware protection module. There you can choose block mode in one option and in another you can choose quarantine enabled or disabled. If you use block mode and quarantine disabled, the malicious files will be blocked but not deleted, so you need to use the File Search and Destroy feature mentioned on the previous answer.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luis&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2025 14:52:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-file-quarantine/m-p/1232972#M8506</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2025-07-01T14:52:01Z</dc:date>
    </item>
  </channel>
</rss>

