- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-27-2024 06:01 PM
Hi,
Please may i know if anyone may have the issue i encounter since early May 2024?
1. Delete a folder (100+ files) from specific endpoint (right click mouse and select delete)
2. From Cortex XDR Query Builder - File Query and Select Action = Delete - filter the particular endpoint hostname/ip
The query no longer returns the file delete/file remove action.
Or am i alone here... :(.
Thank you very much for your advise..
Regards,
05-28-2024 09:23 PM
Hello @chinsiongwong ,
Thank you for writing to Live Community.
Its not a deletion when you delete a file, it just moves it to the Recycle Bin. Shift delete shows up in XQL results and its a proper deletion.
Also, hard delete shows up in XQL when deleting file in Cyvera folder.
If you feel this has answered your query, please let us know by clicking on "mark this as a Solution".
05-28-2024 09:42 PM
Dear Asptail,
This is not the case before the May upgrade.
Before the May upgrade, the query returns all the File_Remove action, being either i use the "del" button, or right click mouse and select delete.
Based on your description, when we delete the file from local drive, yes, it will rename (logical name) and move to recycle.bin.
Have you tried to delete files from network shared drive? Deletion from network drive (either del button, right click mouse and select delete or hard delete), they won't go to the recycle bin. The rename and move to recycle.bin action will not be present. Only file located on your local PC will go to your recycle bin.
How can i still use Cortex XDR for files actions investigation? This is not the case before the May 2024.
Please advise. Thanks.
05-29-2024 10:38 PM
Hello @chinsiongwong ,
This is not the scenario. We have never monitored soft delete and XDR doesn't monitor all the file deletion activities.
If you think this was working previously, then please go head and open a TAC support case for further troubleshooting.
If you feel this has answered your query, please let us know by clicking on "mark this as a Solution".
05-29-2024 11:01 PM
Dear Aspatil,
Sound like the Cortex XDR document need to be update?
Under Endpoint Data Collection --> EDR Data Collected for Windows Endpoints.
Files Events of Create,Write,Delete,Rename,Move, etc collected.
Anyway, thank you very much...the TAC case opened with the support.
Thanks again.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!