Quarantine not working

Reply
Highlighted
L2 Linker

Quarantine not working

Hi Team

We have enabled quarantine for wildfire and local analysis malware verdict. When initiating malware scan from cortex xdr cloud t, the malware's are getting detected and but those are not getting quarantined.Can anyone advice is this how it works?


Accepted Solutions
Highlighted
L4 Transporter

Re: Quarantine not working

Next thing I would check is the agent logs after a quarantine attempt.  

 

https://docs.paloaltonetworks.com/wildfire/8-1/wildfire-admin/submit-files-for-wildfire-analysis/ver...

 

You can use this test PE to trigger a quarantine event.  After the event is complete, open the log file, scroll to the bottom and look for any messages associated with the quarantine attempt.


David Falcon 
MDR Systems Engineer, Cortex
Palo AltoNetworks® 

View solution in original post

Tags (1)

All Replies
Highlighted
L4 Transporter

Re: Quarantine not working

Can you post a screenshot of the Portable Executable and DLL Examination portion of your malware profile?

dfalcon_0-1590513998705.png

 


David Falcon 
MDR Systems Engineer, Cortex
Palo AltoNetworks® 
Highlighted
L2 Linker

Re: Quarantine not working

Screenshot_3.png

Highlighted
L4 Transporter

Re: Quarantine not working

Hi @Marsooq_A-


Just to confirm.  When you go to Endpoint Management > Endpoint Administration, select an endpoint that is failing, right-click and select View Endpoint Policy -- can you see the profile with quarantine enabled applied to the specific machine?

 

dfalcon_0-1590515675290.png

 

 


David Falcon 
MDR Systems Engineer, Cortex
Palo AltoNetworks® 
Highlighted
L2 Linker

Re: Quarantine not working

Yes , I could see the same profile in the policy and this has been confirmed several times.

Highlighted
L4 Transporter

Re: Quarantine not working

Next thing I would check is the agent logs after a quarantine attempt.  

 

https://docs.paloaltonetworks.com/wildfire/8-1/wildfire-admin/submit-files-for-wildfire-analysis/ver...

 

You can use this test PE to trigger a quarantine event.  After the event is complete, open the log file, scroll to the bottom and look for any messages associated with the quarantine attempt.


David Falcon 
MDR Systems Engineer, Cortex
Palo AltoNetworks® 

View solution in original post

Tags (1)
Highlighted
L2 Linker

Re: Quarantine not working

well its works with other endpoints

Tags (1)
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!