Cortex XDR malware scan

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Cortex XDR malware scan

L1 Bithead

Hello ,

 

Does anyone know the difference between the Malware scan initiated from console and Scan initiated by user locally for all drive? Does cortex XDR also scans the memory and registries in the full scan initiated? and how long it should take a system or agent to timeout the scan it it continues in progress for long time.

Cortex XDR 

 

 

 

1 accepted solution

Accepted Solutions

Hi @TejasPatil ,

 

Thank you for reaching out!

 

Indeed your understanding is correct!

 

If the malware scan is initiated on an endpoint by right clicking on its drive letters and if the endpoint happens to have only one drive partition, that is more or less equivalent to a full system scan. What however applicable fact is that the end user will have the capability to abort it if the user has been provided the access to the agent console. Screenshot below:

Screenshot 2023-03-27 at 8.11.53 PM.png

 

The abort is something that would not be possible when the scans are configured to be periodic or server initiated. 

 

 

Hope this helps! Please mark the response as "Accept as Solution" if it resolves your query.

 

 

 

 

 

 

View solution in original post

5 REPLIES 5

L5 Sessionator

Hi @TejasPatil ,

 

Cortex XDR server initiated malware scans vs user initiated scans work on the same logic of examination. The difference is between the coverage of scan and capability to abort. The server initiated scans are full system scans, while the user initiated scans can be local to specific files/folder/drives. Also the server initiated scans cannot be aborted by the end user, while the endpoint initiated scans can be aborted by end user. 

 

Also, there is no ETA to completion for malware scans. For more details and insights on the same, we have a webinar scheduled on 29th of March, 2023, which is based on Active scanning.

Appreciate your presence to have clarification in detail. I am assuming you are in EMEA/JAPAC region and have hyperlinked the image with the registration link for the same. This email was sent to our customers.

Screenshot 2023-03-27 at 10.22.20 AM.png

L1 Bithead

Hello @neelrohit ,

 

Thanks for response. Yes i will be joining the webinar for this topic. 

Could you you please help me to understand the line "The server initiated scans are full system scans, while the user initiated scans can be local to specific files/folder/drives."

for example in 1 machine there is only 1 drive then by initiating scan from user end for that drive will also be system full scan other than criteria of abortion of scan ?

 

 

Hi @TejasPatil ,

 

Thank you for reaching out!

 

Indeed your understanding is correct!

 

If the malware scan is initiated on an endpoint by right clicking on its drive letters and if the endpoint happens to have only one drive partition, that is more or less equivalent to a full system scan. What however applicable fact is that the end user will have the capability to abort it if the user has been provided the access to the agent console. Screenshot below:

Screenshot 2023-03-27 at 8.11.53 PM.png

 

The abort is something that would not be possible when the scans are configured to be periodic or server initiated. 

 

 

Hope this helps! Please mark the response as "Accept as Solution" if it resolves your query.

 

 

 

 

 

 

L1 Bithead

Hello @neelrohit ,

 

One more query on this topic, Does scan initiated locally from Cytool scan start command is different from Malware scan initiated from backend? other than its method of starting the scan

Hi @TejasPatil ,

 

Your understanding is correct.

 

  • 1 accepted solution
  • 2289 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!