XQL Query - File Delete Action

Showing results for 
Show  only  | Search instead for 
Did you mean: 

XQL Query - File Delete Action

L1 Bithead


Please may i know if anyone may have the issue i encounter since early May 2024? 

1. Delete a folder (100+ files) from specific endpoint (right click mouse and select delete)

2. From Cortex XDR Query Builder - File Query and Select Action = Delete - filter the particular endpoint hostname/ip

The query no longer returns the file delete/file remove action. 


Or am i alone here... :(. 


Thank you very much for your advise..










L5 Sessionator

Hello @chinsiongwong ,


Thank you for writing to Live Community.


Its not a deletion  when you delete a file, it just moves it to the Recycle Bin. Shift delete shows up in XQL results and its a proper deletion.


Also, hard delete shows up in XQL when deleting file in Cyvera folder.


If you feel this has answered your query, please let us know by clicking on "mark this as a Solution".



Ashutosh Patil

Dear Asptail,


This is not the case before the May upgrade. 

Before the May upgrade, the query returns all the File_Remove action, being either i use the "del" button, or right click mouse and select delete. 


Based on your description, when we delete the file from local drive, yes, it will rename (logical name) and move to recycle.bin.


Have you tried to delete files from network shared drive? Deletion from network drive (either del button, right click mouse and select delete or hard delete), they won't go to the recycle bin. The rename and move to recycle.bin action will not be present. Only file located on your local PC will go to your recycle bin. 


How can i still use Cortex XDR for files actions investigation? This is not the case before the May 2024. 


Please advise. Thanks.

L5 Sessionator

Hello @chinsiongwong ,


This is not the scenario. We have never monitored soft delete and XDR doesn't monitor all the file deletion activities.


If you think this was working previously, then please go head and open a TAC support case for further troubleshooting.


If you feel this has answered your query, please let us know by clicking on "mark this as a Solution".

Ashutosh Patil

L1 Bithead

Dear Aspatil,



Sound like the Cortex XDR document need to be update?

Under Endpoint Data Collection --> EDR Data Collected for Windows Endpoints.

Files Events of Create,Write,Delete,Rename,Move, etc collected.



Anyway, thank you very much...the TAC case opened with the support.


Thanks again.  

  • 4 replies
  • 78 Subscriptions
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!