<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XDR 7.6.1 seems to ignore exception in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-7-6-1-seems-to-ignore-exception/m-p/460865#M1490</link>
    <description>&lt;P&gt;Hi, Cortex XDR Local Analysis Malware module stops a process called "ClientConsole.exe" (I guess it's a false positive)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've created a global exception for that issue and checked-in client but XDR still blocks this executable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In client log I read these rows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2022/01/25T10:17:33.337+01:00 &amp;lt;Info&amp;gt; VALERIANIT [10128:11292 ] {trapsd:Ptu:Heartbeat:Scheduled:} ignoring admin exception for process: 'clientconsole.exe'&lt;BR /&gt;2022/01/25T10:17:33.337+01:00 &amp;lt;Info&amp;gt; VALERIANIT [10128:11292 ] {trapsd:Ptu:Heartbeat:Scheduled:} ignoring admin exception for process: 'clientconsole.exe'&lt;BR /&gt;2022/01/25T10:17:33.337+01:00 &amp;lt;Info&amp;gt; VALERIANIT [10128:11292 ] {trapsd:Ptu:Heartbeat:Scheduled:} ignoring admin exception for process: 'clientconsole.exe'&lt;BR /&gt;2022/01/25T10:17:33.337+01:00 &amp;lt;Info&amp;gt; VALERIANIT [10128:11292 ] {trapsd:Ptu:Heartbeat:Scheduled:} ignoring admin exception for process: 'clientconsole.exe'&lt;BR /&gt;2022/01/25T10:17:33.337+01:00 &amp;lt;Info&amp;gt; VALERIANIT [10128:11292 ] {trapsd:Ptu:Heartbeat:Scheduled:} ignoring admin exception for process: 'clientconsole.exe'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why XDR ignores my exceptions ????&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jan 2022 09:33:11 GMT</pubDate>
    <dc:creator>Faber</dc:creator>
    <dc:date>2022-01-25T09:33:11Z</dc:date>
    <item>
      <title>XDR 7.6.1 seems to ignore exception</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-7-6-1-seems-to-ignore-exception/m-p/460865#M1490</link>
      <description>&lt;P&gt;Hi, Cortex XDR Local Analysis Malware module stops a process called "ClientConsole.exe" (I guess it's a false positive)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've created a global exception for that issue and checked-in client but XDR still blocks this executable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In client log I read these rows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2022/01/25T10:17:33.337+01:00 &amp;lt;Info&amp;gt; VALERIANIT [10128:11292 ] {trapsd:Ptu:Heartbeat:Scheduled:} ignoring admin exception for process: 'clientconsole.exe'&lt;BR /&gt;2022/01/25T10:17:33.337+01:00 &amp;lt;Info&amp;gt; VALERIANIT [10128:11292 ] {trapsd:Ptu:Heartbeat:Scheduled:} ignoring admin exception for process: 'clientconsole.exe'&lt;BR /&gt;2022/01/25T10:17:33.337+01:00 &amp;lt;Info&amp;gt; VALERIANIT [10128:11292 ] {trapsd:Ptu:Heartbeat:Scheduled:} ignoring admin exception for process: 'clientconsole.exe'&lt;BR /&gt;2022/01/25T10:17:33.337+01:00 &amp;lt;Info&amp;gt; VALERIANIT [10128:11292 ] {trapsd:Ptu:Heartbeat:Scheduled:} ignoring admin exception for process: 'clientconsole.exe'&lt;BR /&gt;2022/01/25T10:17:33.337+01:00 &amp;lt;Info&amp;gt; VALERIANIT [10128:11292 ] {trapsd:Ptu:Heartbeat:Scheduled:} ignoring admin exception for process: 'clientconsole.exe'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why XDR ignores my exceptions ????&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 09:33:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-7-6-1-seems-to-ignore-exception/m-p/460865#M1490</guid>
      <dc:creator>Faber</dc:creator>
      <dc:date>2022-01-25T09:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: XDR 7.6.1 seems to ignore exception</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-7-6-1-seems-to-ignore-exception/m-p/502854#M2178</link>
      <description>&lt;P&gt;Hi Faber,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This may be due to&amp;nbsp;this process not being protected by a module. By default, your exploit security profile protects endpoints from attack techniques that target specific processes. Each exploit protection capability protects a different set of processes that Palo Alto Networks researchers determine are susceptible to attack. If there are no protection modules enabled on the process, no is exception needed. Please reference&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-profiles/add-exploit-security-profile/processes-protected-by-exploit-security-policy" target="_blank"&gt;Processes Protected by Exploit Security Policy (paloaltonetworks.com)&lt;/A&gt;&amp;nbsp;for more details.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are other modules where Process Exceptions will still apply, like Anti-Ransomware Protection, Child Process Protection, but for all Exploit Prevention Modules the process exception makes no difference for an unprotected process.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you're investigation has determined the process is benign, you can add the hash to the Allow List (*best practice is to whitelist by hash) and allow it to be executed on all your endpoints regardless of the WildFire or local analysis verdict.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the UI, Go to &lt;STRONG&gt;Incident Response, Response, Action Center, + New Action&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jtalton_0-1654893682835.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41746i142DF604058E4AFD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jtalton_0-1654893682835.png" alt="jtalton_0-1654893682835.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Enter the SHA-256 hash of the file and click&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jtalton_1-1654893830633.png" style="width: 33px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41747iD8DB2790A11E8A46/image-dimensions/33x39/is-moderation-mode/true?v=v2" width="33" height="39" role="button" title="jtalton_1-1654893830633.png" alt="jtalton_1-1654893830633.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can add up to 100 hashes at once.&amp;nbsp;&lt;BR /&gt;Click &lt;STRONG&gt;Next&lt;/STRONG&gt;.&lt;BR /&gt;Review the summary and click &lt;STRONG&gt;Done&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reference&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-files/manage-file-execution" target="_blank"&gt;Manage File Execution (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 20:46:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-7-6-1-seems-to-ignore-exception/m-p/502854#M2178</guid>
      <dc:creator>jtalton</dc:creator>
      <dc:date>2022-06-10T20:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: XDR 7.6.1 seems to ignore exception</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-7-6-1-seems-to-ignore-exception/m-p/1227962#M8283</link>
      <description>&lt;P&gt;А якщо інцидент генерується модулем "Local Analise", а програма яка генерує це, створює що разу нові файли з новими хеш-сумами?&lt;/P&gt;
&lt;P&gt;Яким чином можна добавити у виключення?&lt;BR /&gt;Бо за шляхом папки&amp;nbsp; яка добавлена у виключення звідки генеруються файли, XDR всерівно блокує.&lt;/P&gt;</description>
      <pubDate>Fri, 02 May 2025 09:35:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-7-6-1-seems-to-ignore-exception/m-p/1227962#M8283</guid>
      <dc:creator>D.Shymanskyi</dc:creator>
      <dc:date>2025-05-02T09:35:01Z</dc:date>
    </item>
  </channel>
</rss>

