Cortex XDR file quarantine

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cortex XDR file quarantine

L0 Member

Hi Team,

 

i have two general questions,

 

1-can i delete a file from multiple endpoints but with different paths from the action centre?

 

2- i understand that cortex can quarantine a malicious file but is there an option to delete it without my interference?

 

1 accepted solution

Accepted Solutions

L4 Transporter

Hi Oasha, 

 

Answering your questions: 

  1. You can use the feature search and destroy files at the Action Center. If you search and destroy by hash, that file will be deleted no matter the path where it is located and even if there are more than one copy of that file at the same endpoint, it will delete it. The agents make a scan once they are installed and keep a database of files with hashes, paths etc.. so every Agent will know where to find that file if it exists.
    Please you can use the doc for more info:
    https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Search-and-destroy-ma...

  2. Related to delete the malicious files without confirmation by the user: At profiles configuration, and specifically Malware Profiles, you will see a different area of configuration options for every malware protection module. There you can choose block mode in one option and in another you can choose quarantine enabled or disabled. If you use block mode and quarantine disabled, the malicious files will be blocked but not deleted, so you need to use the File Search and Destroy feature mentioned on the previous answer. 

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.

 

KR, 

Luis


 

View solution in original post

1 REPLY 1

L4 Transporter

Hi Oasha, 

 

Answering your questions: 

  1. You can use the feature search and destroy files at the Action Center. If you search and destroy by hash, that file will be deleted no matter the path where it is located and even if there are more than one copy of that file at the same endpoint, it will delete it. The agents make a scan once they are installed and keep a database of files with hashes, paths etc.. so every Agent will know where to find that file if it exists.
    Please you can use the doc for more info:
    https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Search-and-destroy-ma...

  2. Related to delete the malicious files without confirmation by the user: At profiles configuration, and specifically Malware Profiles, you will see a different area of configuration options for every malware protection module. There you can choose block mode in one option and in another you can choose quarantine enabled or disabled. If you use block mode and quarantine disabled, the malicious files will be blocked but not deleted, so you need to use the File Search and Destroy feature mentioned on the previous answer. 

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.

 

KR, 

Luis


 

  • 1 accepted solution
  • 285 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!