Cortex XSIAM/XDR - Java File Examination conflict in Policy

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cortex XSIAM/XDR - Java File Examination conflict in Policy

L1 Bithead

Hello Team,

"We have observed that every agent upgraded to version 9.2.1.285 on Citrix devices (VDA, MCS) changes its status to "Partially Protected" after the cyserver restart.

As the number of devices falling into this status has been increasing, we have temporarily modified the policy to prevent further upgrades on these systems until the issue is clarified.

We are attaching several support files collected from affected devices for your review.

Before receiving your findings and review results, we would also like to request instructions for downgrading the agent to the previous version, so that the agent can return to a fully protected state on the affected devices.

Please let us know:
Whether this is a known issue related to version 9.2.1.285 on Citrix VDA / MCS environments.
What is causing the agents to switch to Partially Protected after restart.
What is the recommended and supported procedure to downgrade the agents to the previous version."

Base on above I have created PA Vendor Case asking for help, but since last few weeks I do not get anything which could solve problem so I decide to post here too maybe someone had similar issue. 

 

We have observed that after disabling Java File Examination in the Malware Policy Profile, the previously reported issue no longer occurs. The agents are able to restart cyserver successfully and return to a Fully Protected state in our Citrix environment.

Could you please advise whether the Java File Examination feature could potentially conflict with any exclusions or restrictions configured within the policy?

We are asking because we replicated the policy on a standard Windows Server 2025 environment and performed the following tests:

  1. Citrix policy applied to Windows Server 2025 with Java File Examination enabled – the issue still occurs.
  2. Citrix policy applied to Windows Server 2025 with Java File Examination disabled – the issue does not occur.
  3. Citrix policy applied to Windows Server 2025 with Java File Examination enabled and all policy exceptions removed – the issue does not occur.

Based on these results, it appears there may be an interaction between Java File Examination and one or more policy exclusions. Could this be a known issue? Has anyone encountered similar behavior?

Additionally, could you share any guidance or best practices regarding Java File Examination, particularly any risks or potential side effects associated with incorrectly configured exclusions or policies?

Any recommendations or relevant documentation would be greatly appreciated.

Thank you.

Matti
0 REPLIES 0
  • 156 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!