Search and destroy malicious files
Cortex XDR enables you to effectively hunt down any identified malicious file that may exist on any of your endpoints.
Notice
This functionality requires the following licenses and add-ons:
Cortex XDR Pro per Endpoint license.
Hosts Endpoint license enabled on your tenant.
Host Insights add-on enabled on your tenant.
To take immediate action on known and suspected malicious files, you can search and destroy the files. After identifying the presence of a malicious file, you can immediately destroy the file from any or all endpoints on which the file exists.
The agent builds a local database on the endpoint with a list of all the files, including their path, hash, and additional metadata. Depending on the number of files and the disk size of each endpoint, it can take a few days for Cortex XDR to complete the initial endpoint scan and populate the files database. You cannot search an endpoint until the initial scan is complete and all file hashes are calculated.
After the initial scan is complete, the agent retains a snapshot of the endpoint files inventory. The agent maintains the files database by initiating periodic scans and closely monitoring all actions performed on the files.
You can search for specific files according to the file hash, the file full path, or a partial path using regex parameters from the Action Center or the Query Builder. When you find the file, you can select it in the search results and destroy the file by hash or by path. If you already know the path or hash, you can also destroy a file from the Action Center without performing a search. When you destroy a file by hash, all the file instances on the endpoint are removed.
You can validate a hash against VirusTotal and WildFire to provide additional context before initializing the File Destroy action.
Note
The Cortex XDR agent does not include the following information in the local files inventory:
Information about files that existed on the endpoint and were deleted before the Cortex XDR agent was installed.
Information about files where the file size exceeds the maximum file size for hash calculations that are pre-configured in Cortex XDR .
If the Agent Settings Profile on the endpoint is configured to monitor common file types only, then the local files inventory includes information about these file types only. You cannot search or destroy file types that are not included in the list of common file types.
Prerequisite
The following are prerequisites to enable Cortex XDR to search and destroy files on your endpoints:
Supported platforms:
Windows: Cortex XDR agent version 7.2 or a later. If you plan to enable Search and Destroy on VDI sessions, you must perform the initial scan on the Golden Image.
Mac: Cortex XDR agent version 7.3 or a later release running on macOS version 10.15.4 or later.
Linux: Not supported.
Setup and permissions:
Ensure File Search and Destroy is enabled for your Cortex XDR agent.
Last updated
Was this helpful?
