Active Scanning on Endpoints

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Active Scanning on Endpoints

L3 Networker

We intend to perform scheduled scanning on all endpoints. So we wondered if active scanning was required on all endpoints repeatedly, or if cortex developed its own scan whenever a new file was created or added to the system.

1 REPLY 1

L4 Transporter

Hi @Shashanksinha 

CXDR doesnt work as a traditional AV. We are not the same. We do not scan files continously since this is time consuming and even worst high consumption of resources for very little value. Scanning AVs are based on old signatures that advance attackers never use, which leave you unprotected against real threats.

We are based on behavior. Even though you can still perform scheduled scans, we do not recommend to do it too often to not to waste your assets resources also as mentioned before you wont detect may threats that are not on AV  signatures. 

Scans in CXDR are performed just if you configure them, so not by default

Hope this helps,

Luis 

 

  • 1248 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!