<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Malware scan single file upon custom alert in Endpoint (Traps) Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/malware-scan-single-file-upon-custom-alert/m-p/591366#M1156</link>
    <description>&lt;P&gt;I want to be able to malware scan one single file with Cortex XDR from the administrator perspective and using automation. Does anyone have any experience with this?&lt;/P&gt;
&lt;P&gt;Here is my example:&lt;/P&gt;
&lt;P&gt;I have an SFTP server where files are uploaded to. As each file is uploaded (created) to the server, I want a custom BIOC alert to trigger. This BIOC alert will trigger an automation rule which scans that single file that generated the alert. If the file is malicious, then more work is done (which is outside scope of this question). I do not want to scan the entire server, because this is a waste of compute resources and will slow down operations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From what I have read, XDR can only scan the entire server when done from the admin perspective. Windows endpoint users can scan individual files, but this is outside the reach of the XDR admin. Documentation for reference. &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Scan-an-Endpoint-for-Malware" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Scan-an-Endpoint-for-Malware&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When researching what can be done with cytool and scripting, there is no option to scan an individual file. See "scan" section of this table: &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide/Cytool-for-Windows" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide/Cytool-for-Windows&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone have a possible solution for this?&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jul 2024 15:39:58 GMT</pubDate>
    <dc:creator>Jeremy_Phipps</dc:creator>
    <dc:date>2024-07-08T15:39:58Z</dc:date>
    <item>
      <title>Malware scan single file upon custom alert</title>
      <link>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/malware-scan-single-file-upon-custom-alert/m-p/591366#M1156</link>
      <description>&lt;P&gt;I want to be able to malware scan one single file with Cortex XDR from the administrator perspective and using automation. Does anyone have any experience with this?&lt;/P&gt;
&lt;P&gt;Here is my example:&lt;/P&gt;
&lt;P&gt;I have an SFTP server where files are uploaded to. As each file is uploaded (created) to the server, I want a custom BIOC alert to trigger. This BIOC alert will trigger an automation rule which scans that single file that generated the alert. If the file is malicious, then more work is done (which is outside scope of this question). I do not want to scan the entire server, because this is a waste of compute resources and will slow down operations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From what I have read, XDR can only scan the entire server when done from the admin perspective. Windows endpoint users can scan individual files, but this is outside the reach of the XDR admin. Documentation for reference. &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Scan-an-Endpoint-for-Malware" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Scan-an-Endpoint-for-Malware&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When researching what can be done with cytool and scripting, there is no option to scan an individual file. See "scan" section of this table: &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide/Cytool-for-Windows" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide/Cytool-for-Windows&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone have a possible solution for this?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 15:39:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/malware-scan-single-file-upon-custom-alert/m-p/591366#M1156</guid>
      <dc:creator>Jeremy_Phipps</dc:creator>
      <dc:date>2024-07-08T15:39:58Z</dc:date>
    </item>
  </channel>
</rss>

