- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-26-2026 04:37 AM
Hi everyone,
I need some help/advice.
I’ve been seeing some cases on non-persistent VDIs where we receive alerts such as “Script Engine Activity - 3121803131”.
Basically, the Cortex XDR alert is related to an HTML file hosted on a ShareFile share that I don’t have access to. From what I understand, the HTML file is essentially a web-page template where users fill in some fields, and the information is then saved to a TXT file. That would explain why XDR is triggering this type of alert
My question is: is there any way, through XDR, to retrieve the HTML file for analysis when the file is hosted on a network/ShareFile share?
This could also be useful for other types of incidents. With non-persistent VDIs, if I’m not monitoring the machine at the exact moment the alert occurs, by the time I investigate it, the VDI may already be powered off. At that point, I’ve lost the relevant data because, when the VDI starts again, it is reset to the Golden Image.
I’d like to hear about your experience with these kinds of incidents. How do you normally handle them?
I was also thinking about creating an automation that, whenever an alert is generated on a VDI, automatically triggers a TSF collection. However, I’m not sure whether the HTML file or other relevant artifacts would be included in the TSF.
Any advice or recommendations would be appreciated.
Thanks!
09-07-2026 08:05 AM
Hello @tlmarques ,
Greetings for the day.
Please find below the clarification regarding file retrieval and TSF collection in the current environment.
1. Files on Network Shares:
-Cortex XDR Live Terminal does not support browsing network drives. Files from network shares may also be inaccessible through remote retrieval when the share requires user credentials or does not allow access from the Windows SYSTEM account.
-For such files, we recommend retrieving them directly from the network share or coordinating with the share administrator.
2. TSF Collection: Cortex XDR does not provide a native option to automatically generate a TSF based on a specific alert.
-A TSF is intended for agent troubleshooting and contains Cortex XDR diagnostic information and logs. It does not collect arbitrary files, including HTML/TXT files stored on network shares.
3. Non-Persistent VDI: Since non-persistent VDIs revert to the golden image after logoff, files created during the session may no longer be available.
-However, the EDR telemetry already sent to the Cortex XDR console remains available. The Causality Chain and Execution Chain can be reviewed to determine the process, command line, source path, and related activity.
Note: For recurring legitimate workflows, an appropriate alert exception can be considered after validating the alert details. If the generated files need to be retained, persistent storage or profile redirection should be used.
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thanks & Regards,
S. Subashkar Sekar
09-07-2026 08:05 AM
Hello @tlmarques ,
Greetings for the day.
Please find below the clarification regarding file retrieval and TSF collection in the current environment.
1. Files on Network Shares:
-Cortex XDR Live Terminal does not support browsing network drives. Files from network shares may also be inaccessible through remote retrieval when the share requires user credentials or does not allow access from the Windows SYSTEM account.
-For such files, we recommend retrieving them directly from the network share or coordinating with the share administrator.
2. TSF Collection: Cortex XDR does not provide a native option to automatically generate a TSF based on a specific alert.
-A TSF is intended for agent troubleshooting and contains Cortex XDR diagnostic information and logs. It does not collect arbitrary files, including HTML/TXT files stored on network shares.
3. Non-Persistent VDI: Since non-persistent VDIs revert to the golden image after logoff, files created during the session may no longer be available.
-However, the EDR telemetry already sent to the Cortex XDR console remains available. The Causality Chain and Execution Chain can be reviewed to determine the process, command line, source path, and related activity.
Note: For recurring legitimate workflows, an appropriate alert exception can be considered after validating the alert details. If the generated files need to be retained, persistent storage or profile redirection should be used.
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thanks & Regards,
S. Subashkar Sekar
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

