- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-12-2022 11:25 AM
Hello dear community,
like I saw, there is no possibility to find out the signer, from files which were only downloaded, moved, etc. but not executed.
Why is this not possible?
BR
Rob
10-13-2022 06:40 PM
Hi @RFeyertag as you might be aware, Cortex XDR detects and prevents malicious events during execution. The information that you're looking for is collected by modules invoked during execution.
It is possible to collect the data, but currently it is not part of the functionality.
Would you have any specific use cases where you'd be looking at the metadata of such files (many of which might not be executables) to comprehensively aid in your investigation flows? I assume you're not referring to use cases pertaining to forensic investigations.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!