cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

L5 Sessionator

Hi Oasha, 

 

Answering your questions: 

  1. You can use the feature search and destroy files at the Action Center. If you search and destroy by hash, that file will be deleted no matter the path where it is located and even if there are more than one copy of that file at the same endpoint, it will delete it. The agents make a scan once they are installed and keep a database of files with hashes, paths etc.. so every Agent will know where to find that file if it exists.
    Please you can use the doc for more info:
    https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Search-and-destroy-ma...

  2. Related to delete the malicious files without confirmation by the user: At profiles configuration, and specifically Malware Profiles, you will see a different area of configuration options for every malware protection module. There you can choose block mode in one option and in another you can choose quarantine enabled or disabled. If you use block mode and quarantine disabled, the malicious files will be blocked but not deleted, so you need to use the File Search and Destroy feature mentioned on the previous answer. 

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.

 

KR, 

Luis


 

View solution in original post

Who rated this post