<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HIPS and Host Firewall in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hips-and-host-firewall/m-p/457764#M1436</link>
    <description>&lt;P&gt;Hi MohanKumar1,&amp;nbsp;&lt;/P&gt;&lt;P&gt;xdr agent can perform packet inspection in its own fw (dont take it as a full featured FW as our NGFW) in the link that my colleague&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt;&amp;nbsp;sent you can see at the end of the features list the packet inspection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also realize that we can gather your network traffic and analyse it on the cloud not just with signatures, better than that we perform ML and detect malicious traffic from new attacks that will not be detected by standard signatured based IDS. All this signatures and intelligence is maintained by PANW, you dont need to worry about them.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check out these two docs:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-overview/cortex-xdr-architecture" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-overview/cortex-xdr-architecture&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-release-notes/set-up-network-analysis-and-detection" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-release-notes/set-up-network-analysis-and-detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps also.&lt;/P&gt;&lt;P&gt;KR,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luis&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jan 2022 11:06:54 GMT</pubDate>
    <dc:creator>eluis</dc:creator>
    <dc:date>2022-01-10T11:06:54Z</dc:date>
    <item>
      <title>HIPS and Host Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hips-and-host-firewall/m-p/456896#M1415</link>
      <description>&lt;P&gt;I would like to know whether Cortex XDR has Host Intrusion Prevention and Host Firewall capability. If yes, what is the difference and how to enable.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2022 07:32:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hips-and-host-firewall/m-p/456896#M1415</guid>
      <dc:creator>MohanKumar1</dc:creator>
      <dc:date>2022-01-05T07:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: HIPS and Host Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hips-and-host-firewall/m-p/456936#M1416</link>
      <description>&lt;P&gt;I am looking for the same.&amp;nbsp;&lt;A href="https://www.njmcdirect.tips/" target="_self"&gt;njmcdirect&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jan 2022 03:55:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hips-and-host-firewall/m-p/456936#M1416</guid>
      <dc:creator>Casey69</dc:creator>
      <dc:date>2022-01-06T03:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: HIPS and Host Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hips-and-host-firewall/m-p/457427#M1424</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/194161"&gt;@MohanKumar1&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/205250"&gt;@Casey69&lt;/a&gt;&amp;nbsp;HIPS stands for Host Intrusion Prevention System. Cortex XDR is an EDR solution, and I assume what you're looking for is explained in detail here:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-concepts/about-cortex-xdr-protection.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-concepts/about-cortex-xdr-protection.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, XDR supports Host Firewall capabilities. You can refer to this documentation here:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/hardened-endpoint-security/host-firewall.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/hardened-endpoint-security/host-firewall.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 02:41:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hips-and-host-firewall/m-p/457427#M1424</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-01-07T02:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: HIPS and Host Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hips-and-host-firewall/m-p/457710#M1430</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Thanks for the information. It is confirmed HIPS is not support or not the module available in Cortex XDR as an endpoint security. Or let me know if I am wrong.&lt;/P&gt;&lt;P&gt;Host Firewall is available in EDR.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 00:59:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hips-and-host-firewall/m-p/457710#M1430</guid>
      <dc:creator>MohanKumar1</dc:creator>
      <dc:date>2022-01-10T00:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: HIPS and Host Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hips-and-host-firewall/m-p/457713#M1431</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/194161"&gt;@MohanKumar1&lt;/a&gt;&amp;nbsp;Cortex XDR certainly covers the capabilities of a traditional HIPS, and much more. What features of HIPS are you looking for?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 03:05:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hips-and-host-firewall/m-p/457713#M1431</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-01-10T03:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: HIPS and Host Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hips-and-host-firewall/m-p/457715#M1433</link>
      <description>&lt;P&gt;Does the default XDR update IPS signatures automatically. If yes, How do we check / ensure.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 03:08:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hips-and-host-firewall/m-p/457715#M1433</guid>
      <dc:creator>MohanKumar1</dc:creator>
      <dc:date>2022-01-10T03:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: HIPS and Host Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hips-and-host-firewall/m-p/457717#M1434</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/194161"&gt;@MohanKumar1&lt;/a&gt;&amp;nbsp;the logical equivalent of that would be the "XDR Content Updates", commonly referred to as CU's. You can check the corresponding CU's for an agent via the Endpoint Administration page.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_0-1641784866131.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38551i3ADC9B066363822F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_0-1641784866131.png" alt="bbarmanroy_0-1641784866131.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ref:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/about-content-updates.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/about-content-updates.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can modify the CU updates based on your Agent settings (see &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/customizable-agent-settings/global-agent-configurations.html" target="_self"&gt;brief explanation here&lt;/A&gt;).&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 03:23:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hips-and-host-firewall/m-p/457717#M1434</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-01-10T03:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: HIPS and Host Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hips-and-host-firewall/m-p/457720#M1435</link>
      <description>&lt;P&gt;Thanks, this was the clarification I was looking.&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 04:24:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hips-and-host-firewall/m-p/457720#M1435</guid>
      <dc:creator>MohanKumar1</dc:creator>
      <dc:date>2022-01-10T04:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: HIPS and Host Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hips-and-host-firewall/m-p/457764#M1436</link>
      <description>&lt;P&gt;Hi MohanKumar1,&amp;nbsp;&lt;/P&gt;&lt;P&gt;xdr agent can perform packet inspection in its own fw (dont take it as a full featured FW as our NGFW) in the link that my colleague&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt;&amp;nbsp;sent you can see at the end of the features list the packet inspection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also realize that we can gather your network traffic and analyse it on the cloud not just with signatures, better than that we perform ML and detect malicious traffic from new attacks that will not be detected by standard signatured based IDS. All this signatures and intelligence is maintained by PANW, you dont need to worry about them.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check out these two docs:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-overview/cortex-xdr-architecture" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-overview/cortex-xdr-architecture&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-release-notes/set-up-network-analysis-and-detection" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-release-notes/set-up-network-analysis-and-detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps also.&lt;/P&gt;&lt;P&gt;KR,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luis&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 11:06:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hips-and-host-firewall/m-p/457764#M1436</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2022-01-10T11:06:54Z</dc:date>
    </item>
  </channel>
</rss>

