How to find the Cortex XDR client Policy Profile name from Windows without Local Admin

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

How to find the Cortex XDR client Policy Profile name from Windows without Local Admin

L1 Bithead

As different Cortex XDR Policy profiles can be pushed to different users, it is sometime required to find out what is the current XDR Policy Profile used by a particular endpoint.

 

If the endpoint has local administrator privilege, we could just search in the *.ldb files in the following folder for the name of the profile used.
C:\ProgramData\Cyvera\LocalSystem\Persistence\agent_settings.db\

 

The pattern to look for is in JSON like below:
"mpm":"Xxxxx","agset":"Xxxxxxxxxxxxxxx","restr":"Xxxxxxxxxxxxx","name":"Xxxxxxxxxxxxxx","epm":"Xxxxxx","exceptions":"Xxxxxx)"

 

If the endpoint does not have local administrator privilege, there seems to be no legitimate method to find current XDR Policy Profile used.

 

Before version 7.8, we could at least "Generate Support File" on the XDR client and find the *.ldb files in the generated archive file. But newer versions of XDR after 7.8 encrypts the generated support file.

 

Does anyone know if it is possible to find out the current XDR Policy Profile used by a particular client endpoint without local administrator privilege?

2 REPLIES 2

L3 Networker

Hi Tingmy,

Tracking the policies applied to various agents can easily be done from the Cortex XDR Cloud Tenant, this is the standard way you would track and manage your agent profiles and policies. Is there a particular reason you are needing to do this from the endpoint?

Thanks,
Ben

We are an intermediary security group, so we do not have access to the XDR admin portal. During troubleshooting of end users' issues in previous versions, we find it more convenient to get the users themselves to check the policy profile names on their endpoints, as opposed to emailing the XDR admin.

Before version 7.6.x, it was possible to check the log files directly. During version 7.7.x, we can get the users to generate support files themselves. After version 7.7.x, the support files are encrypted, and require the XDR admins to generate the archive password.

  • 1498 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!