Scan endpoint error

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Scan endpoint error

L3 Networker

Hi, I need help, I have Cortex XDR policy to allow scans on the endpoint, however users are unable to start the scans, the option does not appear

I can only scan, with cmd as administrator (cytool scan start) , in the GUI I can't even do it as administrator:

 

tlmarques_0-1706887670317.png

my configuration:

tlmarques_1-1706887790216.png

 

Please mark the response as "Accept as Solution" if it answers/help your question.

Best regards
Tiago Marques
2 REPLIES 2

L3 Networker

Dear @tlmarques , 

 

Hope you are doing well, and thank you for reaching out to our Live Community. From the above query I believe that you are trying to see how to configure the end users to initiate a full scan from the Cortex XDR interface locally on endpoint. 

 

Please note that a full scan can only be initiated from Cortex XDR portal by navigating to Incident Response → Response → Action Center

 

Please find the document provided below for further details, thank you: 
https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Scan-an...

 

And for the configuration you have provided in the second screenshot, this configuration is used to allow the end user to initiate a right click scan on a file or folder as seen in the screenshot provided below, thank you: 

abdrahman_0-1706976458862.png

 

If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.

L3 Networker

we've that configuration enabled....the problem is the agent...i open a case with support and we found the problem.

For future, if someone have the same problem, check that:

OS version:
In the case of Windows 11, it will show clicking the “Show More Options” in the context menu.

Registry:
This is a registry key related to “Show More Options” in the context menu.
Please check if they are in the registry key.
- HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Cortex.XDR.Scan
- HKEY_CLASSES_ROOT\CLSID\{44303AF8-6F09-4803-8639-9247339BE42D}
- HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\Cortex.XDR.Scan
- HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\Cortex.XDR.Scan

If registry keys are missing, please re-install the agent.

Please mark the response as "Accept as Solution" if it answers/help your question.

Best regards
Tiago Marques
  • 223 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!