Retrieve support file password - Learn how to retrieve the password to access files from the Tech Support File (TSF), which is generated in a zip format protected by an encrypted password. - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-16
Category
Administrator Guide
Abstract

Learn how to retrieve the password to access files from the Tech Support File (TSF), which is generated in a zip format protected by an encrypted password.

From Cortex XDR agent, the Tech Support File (TSF) is generated by the Cytool command log collect in a zip format that is protected by an encrypted password. The TSF file is archived inside another file which includes a metadata file that contains a token. This token is used to retrieve the password to unzip the TSF file.

There are two methods to retrieve the TSF file password:

  1. Go to InventoryEndpointsAll Endpoints

  2. At the top of the page, click the key icon Screenshot_2025-08-04_at_15_40_52.png (Tokens and Passwords) and select Retrieve Support File Password.

  3. In the Retrieve Support File Password dialog box, in the Encrypted Password field, paste the token that you copied from the metadata file located in the saved file when running the Cytool log collect command.

  4. Click the copy button to copy the password displayed and then click Ok. Use the password to unzip the TSF file.

  1. Go to Action Center+All Actions

  2. Right-click the action and select Retrieve Support File Password.

  3. In the Retrieve Support File Password dialog box, in the Encrypted Password field, paste the token that you copied from the metadata file located in the download file.

  4. Click the copy button to copy the password displayed and then click Ok. Use the password to unzip the TSF file.