Cortex XDR Ransomware Protection: Aggressive mode & Resource Optimization

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.

Cortex XDR Ransomware Protection: Aggressive mode & Resource Optimization

L0 Member

Hello Community,

 

I have a question regarding Cortex XDR in Aggressive Mode. During my testing, I noticed that it significantly impacts my machine's performance, as the Cortex XDR agent continuously analyzes the behavior of benign software, such as browsers.

To optimize resource usage and performance, is it possible for Cortex XDR to analyze the behavior of benign software over an extended period (e.g., a month), establish a baseline, and then minimize or stop analyzing that software unless a deviation occurs?

Does Cortex XDR offer a policy or configuration to support this kind of adaptive analysis, or are there other recommendations to mitigate resource usage in Aggressive Mode?

Thank you for your insights!

 

#contex_xdr

#aggressive_mode

1 accepted solution

Accepted Solutions

L3 Networker

Hi @H.Zaw245320 

Thanks for your query on LC!

 

Generally,  we are not recommending to keep Aggressive Mode enabled always to avoid of this type of scenarios and also aggressive mode may make the decoy files distribute to many directries aggressively and be visible to users as well which may cause tampering attempts as well.

 Aggressive mode is part of ransomeware detection and this feature is designed for a scenarios where if user suspects that there is an infection they can enable it in such a scenario but should be disabled after.incase of customer is thinking that there is an infection they can enable it but should be disabled after.

Best,

View solution in original post

1 REPLY 1

L3 Networker

Hi @H.Zaw245320 

Thanks for your query on LC!

 

Generally,  we are not recommending to keep Aggressive Mode enabled always to avoid of this type of scenarios and also aggressive mode may make the decoy files distribute to many directries aggressively and be visible to users as well which may cause tampering attempts as well.

 Aggressive mode is part of ransomeware detection and this feature is designed for a scenarios where if user suspects that there is an infection they can enable it in such a scenario but should be disabled after.incase of customer is thinking that there is an infection they can enable it but should be disabled after.

Best,

  • 1 accepted solution
  • 268 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!