Under which conditions is Local Analysis evoked to evaluate a file before the file is allowed to run?
Local Analysis is a feature of Cortex XDR that allows the agent to evaluate files locally on the endpoint, without sending them to WildFire for analysis. Local Analysis is evoked when the following conditions are met:
The endpoint isdisconnectedfrom the internet or the Cortex XDR management console, and therefore cannot communicate with WildFire.
The verdict from WildFire is of a typeunknown, meaning that WildFire has not yet analyzed the file or has not reached a conclusive verdict.
Local Analysis uses machine learning models to assess the behavior and characteristics of the file and assign it a verdict of either benign, malware, or grayware. If the verdict is malware or grayware, the agent will block the file from running and report it to the Cortex XDR management console. If the verdict is benign, the agent will allow the file to run and report it to the Cortex XDR management console.Reference:
Local Analysis
WildFire File Verdicts
Mira
5 months agoVashti
3 months agoAlana
3 months agoCorazon
4 months agoDallas
4 months agoMicah
4 months agoMelda
4 months agoStefan
5 months agoTina
4 months agoSkye
4 months agoJerilyn
4 months agoAllene
5 months agoEladia
5 months agoLouvenia
5 months agoLayla
5 months agoDanica
5 months agoShawnda
5 months agoShawna
5 months agoShayne
6 months agoFrederica
6 months ago