<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is there a good (and quick) explanation out there of how Cortex XDR works on systems? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-there-a-good-and-quick-explanation-out-there-of-how-cortex/m-p/450722#M1312</link>
    <description>&lt;P&gt;Hello. I'm looking for a 10,000 foot overview explanation that people may have used in the past or anything written up by Palo Alto? We have a lot of people who are used to the way legacy AV systems work and relied heavily on setting recommended exclusions from 3rd party vendors. Exclusions, I believe, are sort of a last resort but I can't seem to convey that properly to the audience questioning why their exclusions aren't placed. Thank you in advance.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Dec 2021 20:13:43 GMT</pubDate>
    <dc:creator>CraigV123</dc:creator>
    <dc:date>2021-12-01T20:13:43Z</dc:date>
    <item>
      <title>Is there a good (and quick) explanation out there of how Cortex XDR works on systems?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-there-a-good-and-quick-explanation-out-there-of-how-cortex/m-p/450722#M1312</link>
      <description>&lt;P&gt;Hello. I'm looking for a 10,000 foot overview explanation that people may have used in the past or anything written up by Palo Alto? We have a lot of people who are used to the way legacy AV systems work and relied heavily on setting recommended exclusions from 3rd party vendors. Exclusions, I believe, are sort of a last resort but I can't seem to convey that properly to the audience questioning why their exclusions aren't placed. Thank you in advance.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 20:13:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-there-a-good-and-quick-explanation-out-there-of-how-cortex/m-p/450722#M1312</guid>
      <dc:creator>CraigV123</dc:creator>
      <dc:date>2021-12-01T20:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a good (and quick) explanation out there of how Cortex XDR works on systems?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-there-a-good-and-quick-explanation-out-there-of-how-cortex/m-p/450734#M1313</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/112301"&gt;@CraigV123&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think something like this is what you are looking for.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/analysis-and-protection-flow.html" target="_blank"&gt;File Analysis and Protection Flow (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/endpoint-protection-capabilities.html" target="_blank"&gt;Protection Capabilities (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 20:20:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-there-a-good-and-quick-explanation-out-there-of-how-cortex/m-p/450734#M1313</guid>
      <dc:creator>fmoixsante</dc:creator>
      <dc:date>2021-12-01T20:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a good (and quick) explanation out there of how Cortex XDR works on systems?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-there-a-good-and-quick-explanation-out-there-of-how-cortex/m-p/450922#M1319</link>
      <description>&lt;P&gt;Thank you for the response. I'll see if I can slim down those explanations any bit. It's been incredible to see the negative reactions from these folks when you tell them that exceptions aren't being placed unless it is the last resort.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 11:33:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-there-a-good-and-quick-explanation-out-there-of-how-cortex/m-p/450922#M1319</guid>
      <dc:creator>CraigV123</dc:creator>
      <dc:date>2021-12-02T11:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a good (and quick) explanation out there of how Cortex XDR works on systems?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-there-a-good-and-quick-explanation-out-there-of-how-cortex/m-p/451089#M1320</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/112301"&gt;@CraigV123&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my opinion, Exceptions are not a last resort. They can certainly be use as such, but they can be used in many other use cases. You need to remember that normal exceptions will &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/exceptions-security-profiles.html" target="_self"&gt;disable security capabilities&lt;/A&gt;, among other things.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of the cases where you would need a Support Exception, is to handle Exploit Alerts as the Exploit profile does not provide any way to add whitelist. The only way to do is to retrieve the Alert data, allow XDR to &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/exceptions-security-profiles/add-a-global-endpoint-policy-exception.html#:~:text=analysis%20security%20event.-,Review%20Advanced%20Analysis%20Exceptions,-With%20Advanced%20Analysis" target="_self"&gt;analyze&lt;/A&gt; it, if if XDR cannot provide an Exception, you need to open a TAC case, upload the alert data file and they will be able to debug it. TAC will be able to tell you if the Exploit alert is a false/true positive. If it is a false positive, they will provide a &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/exceptions-security-profiles/add-exceptions-profile.html#:~:text=To%20configure%20a-,Support%20Exception,-%3A" target="_self"&gt;Support Exception&lt;/A&gt; that will take care of the compatibility issue on that specific Exploit module.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this makes Exceptions a bit more clear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 21:48:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-there-a-good-and-quick-explanation-out-there-of-how-cortex/m-p/451089#M1320</guid>
      <dc:creator>fmoixsante</dc:creator>
      <dc:date>2021-12-02T21:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a good (and quick) explanation out there of how Cortex XDR works on systems?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-there-a-good-and-quick-explanation-out-there-of-how-cortex/m-p/451235#M1321</link>
      <description>&lt;P&gt;Thanks for the additional insight to the exceptions. Our old AV system had exceptions for everything it seemed and made the platform look like swiss cheese with all of the security "holes" in it. XDR has been a total 180 to that system but we still have users that insist on having the vendor recommended exceptions in place as a "comfort blanket." Not because they're being blocked but because of how they remember legacy AV systems operate... still working on that culture change I guess you can say. Anyways, thank you again for your help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Dec 2021 12:22:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-there-a-good-and-quick-explanation-out-there-of-how-cortex/m-p/451235#M1321</guid>
      <dc:creator>CraigV123</dc:creator>
      <dc:date>2021-12-03T12:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a good (and quick) explanation out there of how Cortex XDR works on systems?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-there-a-good-and-quick-explanation-out-there-of-how-cortex/m-p/451265#M1322</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/112301"&gt;@CraigV123&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PANW provides already a set of compatibility policies in the form of Content Updates, which are provided weekly/biweekly automatically to every customer's tenant and automatically to all XDR agents.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, thank you for your interest in our product, and please keep coming back here whenever you have any doubts or seeking advice.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Dec 2021 15:57:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-there-a-good-and-quick-explanation-out-there-of-how-cortex/m-p/451265#M1322</guid>
      <dc:creator>fmoixsante</dc:creator>
      <dc:date>2021-12-03T15:57:46Z</dc:date>
    </item>
  </channel>
</rss>

