- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-14-2023 02:20 AM
Today, one of the most common techniques for a intruder today is to use a valid backup system to make a image of the system and in what way steal all the data of the server..
Werefore i want a new module in the Cortex XDR what will detect the backup software.
- The first installed backup software will just be notified upon.
- As a admin i should be whitelist the backup software we are using, and the destination of the backups.
- If a second backup software is installed on a computer it should be blocked by default so we can review it before allowing it. (except if it's in the whitelist)
- If a new destination is set up in current backup software, it should be blocked untill we allow the destination.
This should be implemented in the Cortex XDR so we can avoid exfiltration of the systems data to unknow destinations. i don't want my data to be stealed by "valid" backup softwares.
08-14-2023 02:46 AM
Hi @Jonas_Crossnet ,
Thanks for your message !
For a new feature request, please reach out to your local SE.
They can create a feature request for you to which you and others can add their vote.
Kind regards,
-Kim.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!