- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-26-2026 04:37 AM
Hi everyone,
I need some help/advice.
I’ve been seeing some cases on non-persistent VDIs where we receive alerts such as “Script Engine Activity - 3121803131”.
Basically, the Cortex XDR alert is related to an HTML file hosted on a ShareFile share that I don’t have access to. From what I understand, the HTML file is essentially a web-page template where users fill in some fields, and the information is then saved to a TXT file. That would explain why XDR is triggering this type of alert
My question is: is there any way, through XDR, to retrieve the HTML file for analysis when the file is hosted on a network/ShareFile share?
This could also be useful for other types of incidents. With non-persistent VDIs, if I’m not monitoring the machine at the exact moment the alert occurs, by the time I investigate it, the VDI may already be powered off. At that point, I’ve lost the relevant data because, when the VDI starts again, it is reset to the Golden Image.
I’d like to hear about your experience with these kinds of incidents. How do you normally handle them?
I was also thinking about creating an automation that, whenever an alert is generated on a VDI, automatically triggers a TSF collection. However, I’m not sure whether the HTML file or other relevant artifacts would be included in the TSF.
Any advice or recommendations would be appreciated.
Thanks!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

