- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-10-2026 02:16 AM
Hello, Everyone!
1. An Android device is connected to a computer where XDR is installed.
2. After the connection (Android-Computer), the user accesses the Android device’s folder from the computer and copies file A from the computer to the Android device.
3. On the computer, the copied file A on the Android device is renamed or copied to a different directory in the Android.
In this scenario, I would like to know:
Whether these actions are logged in XDR, and
Whether these logs can be searched using XQL.
I would appreciate insights from experts. Thank you.
#XQL #MTP
04-13-2026 06:39 AM
Hello @Y.SONG464633 ,
Greetings for the day.
Based on the internal research and technical support cases, here are the answers to your scenario regarding Android devices and Cortex XDR:
1. Whether these actions are logged in XDR
In the scenario described (Android device connected to a computer), file actions such as copying, renaming, or moving files within the Android device are generally not logged by Cortex XDR.
Because the agent does not capture these specific MTP-based file operations, they cannot be searched using XQL.
However, if the device were a standard USB Flash Drive (which mounts as a storage volume), you could search for these actions.
For comparison, with a standard removable drive, you could use a query like the one below to find file writes:
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thanks & Regards,
S. Subashkar Sekar
04-13-2026 06:39 AM
Hello @Y.SONG464633 ,
Greetings for the day.
Based on the internal research and technical support cases, here are the answers to your scenario regarding Android devices and Cortex XDR:
1. Whether these actions are logged in XDR
In the scenario described (Android device connected to a computer), file actions such as copying, renaming, or moving files within the Android device are generally not logged by Cortex XDR.
Because the agent does not capture these specific MTP-based file operations, they cannot be searched using XQL.
However, if the device were a standard USB Flash Drive (which mounts as a storage volume), you could search for these actions.
For comparison, with a standard removable drive, you could use a query like the one below to find file writes:
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thanks & Regards,
S. Subashkar Sekar
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

