- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-03-2024 07:27 AM
Hello @Arman_Zaheri
Thanks for reaching out on LiveCommunity!
When the agent quarantines malware, it moves the file from the location on a local or removable drive to a local quarantine folder (%PROGRAMDATA%\Cyvera\Quarantine
) where it isolates the file. This prevents the file from attempting to run again from the same path or causing any harm to your endpoints. Durning this process the extension of the file is also changed to ".qtn". Accessing this file in this format will not help with analysis in a sandbox environment. Hence if you want to download a file from quarantine folder you need to restore it first.
Please refer below link for more details.
Please click Accept as Solution to acknowledge that the answer to your question has been provided.