From Cortex XDR agent, the Tech Support File (TSF) is generated by the Cytool command `log collect` in a zip format that is protected by an encrypted password. The TSF file is archived inside another file which includes a metadata file that contains a token. This token is used to retrieve the password to unzip the TSF file.
There are two methods to retrieve the TSF file password in Cortex XSIAM:
### Retrieve the password from the endpoint, using the server Tokens and Passwords option.
1. Go to **Inventory →** **Endpoints** → **All Endpoints.**
2. At the top of the page, click the key icon <img src="/docs/images/5496cfe947544b6a.png" alt="Screenshot_2025-08-04_at_15_40_52.png" data-size="line"> (**Tokens and Passwords**) and select **Retrieve Support File Password**.
3. In the **Retrieve Support File Password** dialog box, in the **Encrypted Password** field, paste the token that you copied from the metadata file located in the saved file when running the Cytool log collect command.
4. Click the copy button to copy the password displayed and then click **Ok**. Use the password to unzip the TSF file.
### Retrieve the password for the TSF file from the server Action Center.
1. Go to **Action Center → All Actions.**
2. Right-click the action and select **Retrieve Support File Password**.
3. In the **Retrieve Support File Password** dialog box, in the **Encrypted Password** field, paste the token that you copied from the metadata file located in the download file.
4. Click the copy button to copy the password displayed and then click **Ok**. Use the password to unzip the TSF file.