- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-04-2023 10:37 PM - edited 11-04-2023 10:40 PM
Hi LIVEcommunity,
Is there a way for Cortex XDR to take the cleanest snapshot of windows so there is a point where we can rollback the endpoint after an attack?
Windows has a feature called Volume Shadow Copy Service (VSS) but can Cortex XDR use this after a ransomware attack? What if the VSS is corrupted, how can Cortex XDR protect the VSS and rollback to the cleanest state of the endpoint?
We are trying to compete with other product that has a feature like this, but I cannot find documentation stating how can Cortex XDR accomplish this task.
I hope experts in this community can guide us. Thank you.
- Jim