- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-17-2024 01:50 AM
Unable to clear user's APPDATA...for tshoot (application upgraded) we need delete all files and folder on users APPDATA , but the system prevent this.
I try stop services and delete files/folders, but not work.(XDR create a incident - Suspicious File Modification)
someone have this problem on Cortex XDR
04-17-2024 06:44 AM
Hi @tlmarques, thanks for reaching us using the Live Community.
What protection module is blocking the action?
Once you have indentified it, you can create an exception for the module and the required folder to except any agent action over it.
If this post answers your question, please mark it as the solution.
04-18-2024 06:52 AM
Thanks... but the problem is, I need to delete a user profile, and the Cortex XDR creates dummy files in folders (files for ransomware protection). When I stop the services and try 'rmdir /S userfolder', the system closes the cmd window.
On the tenant, an alert appears indicating "XDR created an incident - Suspicious File Modification".
The exception for this alert is "Process Name - cmd.exe and Module Name - Anti-Ransomware Protection"... we can't do that; it's very dangerous.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!