Quarantining files about 300 MB / Hunting big Files

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Quarantining files about 300 MB / Hunting big Files

L4 Transporter

Hello dear community, 

 

what happens with quarantined files, which have 300 MB? 

 

I can't download it from the action center like I am used to. 

 

Yes, I saw they are moved to %PROGRAMDATA%\Cyvera\Quarantine), but can I get it from there?

 

Would you hunt big files, which are executed by users? 

 

BR

 

Rob

1 accepted solution

Accepted Solutions

Yes, if you need the files at the moment, it needs to be online. If it is not, the task is hold as "Pending" until the client connects again with the console.

I tried to retrieve files with the route %PROGRAMDATA%\Cyvera\QuarantineV2\*.* and all came encrypted.

 

Thanks!

JM

JM

View solution in original post

4 REPLIES 4

L4 Transporter

Hi @RFeyertag, thanks for contacting us in the Live Community.

I'll do some checks and I'll be back with more information about retrieving files from quarantine (without restoring them).

 

Is really hard to find a 300MB malware file, maybe a zipped one containing it. Is a size that is really hard to manage on any solution.

 

JM

L4 Transporter

@RFeyertag, I did some tests, and the files retrieved from the Qarantine folder, comes encrypted with a .qtn extension.

 

The option that comes to my mind, is:

- Restore the file to the original location.

- Retrieve it using the Action Center as you usually do.

 

The max size of the files is 500MB.

 

Please, le me know if it works for you, and mark the answer as the solution.

 

Thanks!

JM

Thank you so much for your attention to this question. 

In my mind I was able to get the file from quarantine. But I think in this case it is too big or the isolated endpoint didn't allow it. Maybe the client also wasn't online anymore. 

So, if I retreive files from quarantaine, the client needs to be online, right? 

 

I will try your suggestion, thank you! 

BR

 

Rob

Yes, if you need the files at the moment, it needs to be online. If it is not, the task is hold as "Pending" until the client connects again with the console.

I tried to retrieve files with the route %PROGRAMDATA%\Cyvera\QuarantineV2\*.* and all came encrypted.

 

Thanks!

JM

JM
  • 1 accepted solution
  • 973 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!