cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

L5 Sessionator

Hello @Arman_Zaheri 

 

Thanks for reaching out on LiveCommunity!

When the agent quarantines malware, it moves the file from the location on a local or removable drive to a local quarantine folder (%PROGRAMDATA%\Cyvera\Quarantine) where it isolates the file. This prevents the file from attempting to run again from the same path or causing any harm to your endpoints. Durning this process the extension of the file is also changed to ".qtn". Accessing this file in this format will not help with analysis in a sandbox environment. Hence if you want to download a file from quarantine folder you need to restore it first.

Please refer below link for more details.

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-Quar...

 

Please click Accept as Solution to acknowledge that the answer to your question has been provided.

View solution in original post

Who rated this post