Skip to main content
Solved

Cortex XDR as Antivirus Engine


geschnei
Forum|alt.badge.img

Is anybody using Cortex XDR along with Veeam? It should be fairly easy to extend the Antivirus definition file, but I can’t find any information about how (or even if) Cortex can be called to scan a specific file.

Best answer by geschnei

After discussing the issue further with my colleague who is responsible for our AV we came to the conclusion that it might be better to use Defender (or other classical AV solutions) for these scans, since Cortex XDR is a behavioral scanner and might not be the best solution for pure file scanning.

We ended up editing the AV definition XML file on the mount server to change the IsPortableSoftware='false' of the Defender entry to IsPortableSoftware='true', so Veeam ignores the disabled state of the Defender service. Now Veeam is utilizing Windows Defender for SureBackup and Secure Restore while Cortex keeps scanning for behavioral anomalies in the background.

Still, if other people are using Cortex XDR I’d be interested in their opinions on this matter.

View original
Did this topic help you find an answer to your question?

6 comments

Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8518 comments
  • June 13, 2024

Not sure if that AV is even supported with Veeam.  Check here for how the AV process works and configurations - Antivirus Configuration File - User Guide for VMware vSphere (veeam.com)


renner-stefan
Forum|alt.badge.img

Any AV is supported as you can write your definition file on your own. The once we liste in the definiton file ourselves are just the ones we tested in QA. I will keep you posted on Cortex XDR


Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8518 comments
  • June 13, 2024
renner-stefan wrote:

Any AV is supported as you can write your definition file on your own. The once we liste in the definiton file ourselves are just the ones we tested in QA. I will keep you posted on Cortex XDR

Thanks for clarifying this.  Looking forward to the results.


geschnei
Forum|alt.badge.img
  • Author
  • Not a newbie anymore
  • 2 comments
  • Answer
  • June 14, 2024

After discussing the issue further with my colleague who is responsible for our AV we came to the conclusion that it might be better to use Defender (or other classical AV solutions) for these scans, since Cortex XDR is a behavioral scanner and might not be the best solution for pure file scanning.

We ended up editing the AV definition XML file on the mount server to change the IsPortableSoftware='false' of the Defender entry to IsPortableSoftware='true', so Veeam ignores the disabled state of the Defender service. Now Veeam is utilizing Windows Defender for SureBackup and Secure Restore while Cortex keeps scanning for behavioral anomalies in the background.

Still, if other people are using Cortex XDR I’d be interested in their opinions on this matter.


Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8518 comments
  • June 14, 2024
geschnei wrote:

After discussing the issue further with my colleague who is responsible for our AV we came to the conclusion that it might be better to use Defender (or other classical AV solutions) for these scans, since Cortex XDR is a behavioral scanner and might not be the best solution for pure file scanning.

We ended up editing the AV definition XML file on the mount server to change the IsPortableSoftware='false' of the Defender entry to IsPortableSoftware='true', so Veeam ignores the disabled state of the Defender service. Now Veeam is utilizing Windows Defender for SureBackup and Secure Restore while Cortex keeps scanning for behavioral anomalies in the background.

Still, if other people are using Cortex XDR I’d be interested in their opinions on this matter.

Glad you were able to come to a resolution on this one.  I am still interested as well in hearing about the Cortex XDR solution just for my own learning. 😁


dloseke
Forum|alt.badge.img+8
  • Veeam Vanguard
  • 1447 comments
  • June 17, 2024

I appreciate you marking your own response as the answer as that’s very insightful for all.  I haven’t ventured too much into this integration, but I hadn’t considered the difference of an XDR vs antivirus/antimalware engine in this scenario.