Under which conditions is Local Analysis evoked to evaluate a file before the file is allowed to run?
Local Analysis is a feature of Cortex XDR that allows the agent to evaluate files locally on the endpoint, without sending them to WildFire for analysis. Local Analysis is evoked when the following conditions are met:
The endpoint isdisconnectedfrom the internet or the Cortex XDR management console, and therefore cannot communicate with WildFire.
The verdict from WildFire is of a typeunknown, meaning that WildFire has not yet analyzed the file or has not reached a conclusive verdict.
Local Analysis uses machine learning models to assess the behavior and characteristics of the file and assign it a verdict of either benign, malware, or grayware. If the verdict is malware or grayware, the agent will block the file from running and report it to the Cortex XDR management console. If the verdict is benign, the agent will allow the file to run and report it to the Cortex XDR management console.Reference:
Local Analysis
WildFire File Verdicts
Mira
11 months agoVashti
9 months agoAlana
9 months agoCorazon
10 months agoDallas
10 months agoMicah
10 months agoMelda
10 months agoStefan
11 months agoTina
10 months agoSkye
10 months agoJerilyn
10 months agoAllene
11 months agoEladia
11 months agoLouvenia
11 months agoLayla
11 months agoDanica
12 months agoShawnda
11 months agoShawna
11 months agoShayne
12 months agoFrederica
12 months ago