Cortex XdR

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cortex XdR

L1 Bithead

Is it possible to set a policy for the file size  in cortex Xdr /Cortex Xdr pro? 

Requirement: The limited size(configured size if possible to set policy)  of file can only be shared between the endpoint 

4 REPLIES 4

L3 Networker

Can you provide more details please?

Kind Regards
KS

L5 Sessionator

Hi @KiranBashyal what kind of sharing are you referring to? Is it file sharing over SMB or uploading files to WF? As you are aware, Cortex XDR manages endpoint protection of malicious behavior. If you're looking at volume quotas, that should be an operating system specific control that are centrally managed by existing solutions.

L1 Bithead

Sharing of files from endpoint to endpoint, Endpoints cud be on same network or different network. Simply the sharing should contain the size restriction. i.e upto 500mb of any files can be shared from certain endpoint

 

Hi Kiran, it is not possible to restrict such features OOB.

However, there are Analytics detectors to raise alerts of such a nature. Here's an example for HTTPS (https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-analytics-alert-reference/cortex-xdr-...)

 

You can also use the network_story preset to query for upload sizes and convert it into a BIOC for alerting. Look at the field action_total_upload.

 

bbarmanroy_1-1647247125127.png

 

  • 2350 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!