XDR - Unable to clear user's APPDATA

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

XDR - Unable to clear user's APPDATA

L3 Networker

Unable to clear user's APPDATA...for tshoot (application upgraded) we need delete all files and folder on users APPDATA , but the system prevent this.

 

I try stop services and delete files/folders, but not work.(XDR create a incident - Suspicious File Modification)

 

 

someone have this problem on Cortex XDR 

Best regards
Tiago Marques
2 REPLIES 2

L4 Transporter

Hi @tlmarques, thanks for reaching us using the Live Community.

 

What protection module is blocking the action?

Once you have indentified it, you can create an exception for the module and the required folder to except any agent action over it.

 

 

If this post answers your question, please mark it as the solution.

JM

 

Thanks... but the problem is, I need to delete a user profile, and the Cortex XDR  creates dummy files in folders (files for ransomware protection). When I stop the services and try 'rmdir /S userfolder', the system closes the cmd window.

On the tenant, an alert appears indicating "XDR created an incident - Suspicious File Modification".


The exception for this alert is "Process Name - cmd.exe and Module Name - Anti-Ransomware Protection"... we can't do that; it's very dangerous.



Best regards
Tiago Marques
  • 225 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!