- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.
12-23-2024 11:40 PM
Hello Community,
I have a question regarding Cortex XDR in Aggressive Mode. During my testing, I noticed that it significantly impacts my machine's performance, as the Cortex XDR agent continuously analyzes the behavior of benign software, such as browsers.
To optimize resource usage and performance, is it possible for Cortex XDR to analyze the behavior of benign software over an extended period (e.g., a month), establish a baseline, and then minimize or stop analyzing that software unless a deviation occurs?
Does Cortex XDR offer a policy or configuration to support this kind of adaptive analysis, or are there other recommendations to mitigate resource usage in Aggressive Mode?
Thank you for your insights!
#contex_xdr
#aggressive_mode
01-02-2025 02:58 AM
Hi @H.Zaw245320
Thanks for your query on LC!
Generally, we are not recommending to keep Aggressive Mode enabled always to avoid of this type of scenarios and also aggressive mode may make the decoy files distribute to many directries aggressively and be visible to users as well which may cause tampering attempts as well.
Aggressive mode is part of ransomeware detection and this feature is designed for a scenarios where if user suspects that there is an infection they can enable it in such a scenario but should be disabled after.incase of customer is thinking that there is an infection they can enable it but should be disabled after.
Best,
01-02-2025 02:58 AM
Hi @H.Zaw245320
Thanks for your query on LC!
Generally, we are not recommending to keep Aggressive Mode enabled always to avoid of this type of scenarios and also aggressive mode may make the decoy files distribute to many directries aggressively and be visible to users as well which may cause tampering attempts as well.
Aggressive mode is part of ransomeware detection and this feature is designed for a scenarios where if user suspects that there is an infection they can enable it in such a scenario but should be disabled after.incase of customer is thinking that there is an infection they can enable it but should be disabled after.
Best,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!