<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Different process exception on Exception Profile and Folder Allow List on Malware profile in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/different-process-exception-on-exception-profile-and-folder/m-p/429545#M1000</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191261"&gt;@Muhammad-Rusli&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi Expert,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please give me advice, So I have assesment for exclusion folder and file .exe and file etc extension.&lt;/P&gt;&lt;P&gt;The asessment from Sophos for agent existing my customer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The example exclusion files like a below :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Windows\System32\backgroundTaskHost.exe&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Program FIles (x86)\Microsoft SQL Server\&lt;/P&gt;&lt;P&gt;*.txt&lt;/P&gt;&lt;P&gt;, more again&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my question is, where I can add the exclusion folder/files, Malware Profile or Exception Profile?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Hello Muhammad-Rusli,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It would be a best practice to first check the details of the incident and alarms within it to understand why the application was prevented, alert sources and the need for the exception. You can add more granular detail to your baseline policies configuring&amp;nbsp; an exceptions profile. (f.e&amp;nbsp; Process Exceptions, Support Exceptions, Behavioral Threat Protection Rule Exceptions, Local Analysis Rules Exceptions&lt;/P&gt;&lt;DIV class="nav-link ng-star-inserted"&gt;Advanced Analysis Exception or Digital Signer Exceptions). With a Malware profile you can add files and folders to an allow list to exclude them from examination.&lt;/DIV&gt;&lt;DIV class="nav-link ng-star-inserted"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="nav-link ng-star-inserted"&gt;Endpoint Security Profiles:&lt;/DIV&gt;&lt;DIV class="nav-link ng-star-inserted"&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-profiles.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-profiles.html&lt;/A&gt;&lt;/DIV&gt;&lt;DIV class="nav-link ng-star-inserted"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="nav-link ng-star-inserted"&gt;Exceptions security profiles:&lt;/DIV&gt;&lt;DIV class="nav-link ng-star-inserted"&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/exceptions-security-profiles.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/exceptions-security-profiles.html&lt;/A&gt;&lt;/DIV&gt;&lt;DIV class="nav-link ng-star-inserted"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Thu, 26 Aug 2021 20:01:10 GMT</pubDate>
    <dc:creator>yalonso</dc:creator>
    <dc:date>2021-08-26T20:01:10Z</dc:date>
    <item>
      <title>Different process exception on Exception Profile and Folder Allow List on Malware profile</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/different-process-exception-on-exception-profile-and-folder/m-p/428786#M992</link>
      <description>&lt;P&gt;Hi Expert,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please give me advice, So I have assesment for exclusion folder and file .exe and file etc extension.&lt;/P&gt;&lt;P&gt;The asessment from Sophos for agent existing my customer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The example exclusion files like a below :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Windows\System32\backgroundTaskHost.exe&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Program FIles (x86)\Microsoft SQL Server\&lt;/P&gt;&lt;P&gt;*.txt&lt;/P&gt;&lt;P&gt;, more again&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my question is, where I can add the exclusion folder/files, Malware Profile or Exception Profile?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2021 15:30:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/different-process-exception-on-exception-profile-and-folder/m-p/428786#M992</guid>
      <dc:creator>Muhammad-Rusli</dc:creator>
      <dc:date>2021-08-24T15:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: Different process exception on Exception Profile and Folder Allow List on Malware profile</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/different-process-exception-on-exception-profile-and-folder/m-p/429545#M1000</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191261"&gt;@Muhammad-Rusli&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi Expert,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please give me advice, So I have assesment for exclusion folder and file .exe and file etc extension.&lt;/P&gt;&lt;P&gt;The asessment from Sophos for agent existing my customer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The example exclusion files like a below :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Windows\System32\backgroundTaskHost.exe&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Program FIles (x86)\Microsoft SQL Server\&lt;/P&gt;&lt;P&gt;*.txt&lt;/P&gt;&lt;P&gt;, more again&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my question is, where I can add the exclusion folder/files, Malware Profile or Exception Profile?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Hello Muhammad-Rusli,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It would be a best practice to first check the details of the incident and alarms within it to understand why the application was prevented, alert sources and the need for the exception. You can add more granular detail to your baseline policies configuring&amp;nbsp; an exceptions profile. (f.e&amp;nbsp; Process Exceptions, Support Exceptions, Behavioral Threat Protection Rule Exceptions, Local Analysis Rules Exceptions&lt;/P&gt;&lt;DIV class="nav-link ng-star-inserted"&gt;Advanced Analysis Exception or Digital Signer Exceptions). With a Malware profile you can add files and folders to an allow list to exclude them from examination.&lt;/DIV&gt;&lt;DIV class="nav-link ng-star-inserted"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="nav-link ng-star-inserted"&gt;Endpoint Security Profiles:&lt;/DIV&gt;&lt;DIV class="nav-link ng-star-inserted"&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-profiles.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-profiles.html&lt;/A&gt;&lt;/DIV&gt;&lt;DIV class="nav-link ng-star-inserted"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="nav-link ng-star-inserted"&gt;Exceptions security profiles:&lt;/DIV&gt;&lt;DIV class="nav-link ng-star-inserted"&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/exceptions-security-profiles.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/exceptions-security-profiles.html&lt;/A&gt;&lt;/DIV&gt;&lt;DIV class="nav-link ng-star-inserted"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 26 Aug 2021 20:01:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/different-process-exception-on-exception-profile-and-folder/m-p/429545#M1000</guid>
      <dc:creator>yalonso</dc:creator>
      <dc:date>2021-08-26T20:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: Different process exception on Exception Profile and Folder Allow List on Malware profile</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/different-process-exception-on-exception-profile-and-folder/m-p/464215#M1545</link>
      <description>&lt;P&gt;I'm also having a difficult time looking for file extensions exclusions if that is even possible?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 15:13:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/different-process-exception-on-exception-profile-and-folder/m-p/464215#M1545</guid>
      <dc:creator>magarcias</dc:creator>
      <dc:date>2022-02-08T15:13:03Z</dc:date>
    </item>
  </channel>
</rss>

