Signer of a file in file operations

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Signer of a file in file operations

L4 Transporter

Hello dear community, 

 

like I saw, there is no possibility to find out the signer, from files which were only downloaded, moved, etc. but not executed. 

 

Why is this not possible?

 

BR

 

Rob

1 REPLY 1

L5 Sessionator

Hi @RFeyertag as you might be aware, Cortex XDR detects and prevents malicious events during execution. The information that you're looking for is collected by modules invoked during execution. 

It is possible to collect the data, but currently it is not part of the functionality. 

Would you have any specific use cases where you'd be looking at the metadata of such files (many of which might not be executables) to comprehensively aid in your investigation flows? I assume you're not referring to use cases pertaining to forensic investigations.

  • 1173 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!