<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How most decisions are made by Cortex XDR ? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-most-decisions-are-made-by-cortex-xdr/m-p/469984#M1600</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/210067"&gt;@Balaraju&lt;/a&gt;&amp;nbsp;this depends on the configuration of your Malware profiles.&lt;/P&gt;&lt;P&gt;Assuming your profile is configured with Wildfire (WF) analysis enabled and configured to blocl/report for known samples or run Local Analysis for unknown verdicts, your explanation is correct for both points. However, this does not include the reaction of post-execution modules like Behavioral Threat Protection, ransomware, NPI etc. Even if WF verdicts are benign, post-execution modules will continue to operate independently and can mitigate threats in-flight.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have any statistical data at hand - but again, it depends on the tenant configuration. Some organizations might have WF disabled, and thus, solely depend on Local Analysis verdicts. Verdicts can vary between industry verticals, types of software used, internet access control (air-gapped systems vs direct internet exposure), administrative rights of endpoint user, firewall configurations and the list goes on. So,&amp;nbsp;&lt;EM&gt;it depends!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please refer to this detailed documentation on Cortex XDR file analysis and protection flows:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/analysis-and-protection-flow.html#idc8514e04-490b-498a-b9ca-b68dfc5be3d4" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/analysis-and-protection-flow.html#idc8514e04-490b-498a-b9ca-b68dfc5be3d4&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Mar 2022 04:56:09 GMT</pubDate>
    <dc:creator>bbarmanroy</dc:creator>
    <dc:date>2022-03-03T04:56:09Z</dc:date>
    <item>
      <title>How most decisions are made by Cortex XDR ?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-most-decisions-are-made-by-cortex-xdr/m-p/469818#M1599</link>
      <description>&lt;P&gt;Greetings ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using Cortex XDR Prevent and keen to know how most decisions are made by Cortex XDR about File/process/macro being malicious or not ?&amp;nbsp; So assume there are no Hash exceptions and need to know if below is true :&lt;/P&gt;&lt;P&gt;- First Wildfire cache is checked and if verdict for sample is&amp;nbsp; available ,its used&amp;nbsp; and it becomes final&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Second if sample is not in Wildfire cache then&amp;nbsp; static analysis is done and its decision is used and parallelly sample is sent for WildFire analysis and once verdict is received it takes priority over static analysis&amp;nbsp; and if WildFire verdict is 'Unknown' then Static Analysis verdict is final . Also till the time verdict is received from Wildfire the local analysis verdict is valid .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can somebody confirm if above is true understanding or if Iam wrong anywhere ?&lt;/P&gt;&lt;P&gt;Secondly will appreciate if any statistical information is shared about above like in most cases whose verdict is used in most cases ? between Static Analysis and Wildfire .&lt;/P&gt;&lt;P&gt;Thirdly need to know how often are verdicts different and are they same in most cases ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 15:37:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-most-decisions-are-made-by-cortex-xdr/m-p/469818#M1599</guid>
      <dc:creator>Balaraju</dc:creator>
      <dc:date>2022-03-02T15:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: How most decisions are made by Cortex XDR ?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-most-decisions-are-made-by-cortex-xdr/m-p/469984#M1600</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/210067"&gt;@Balaraju&lt;/a&gt;&amp;nbsp;this depends on the configuration of your Malware profiles.&lt;/P&gt;&lt;P&gt;Assuming your profile is configured with Wildfire (WF) analysis enabled and configured to blocl/report for known samples or run Local Analysis for unknown verdicts, your explanation is correct for both points. However, this does not include the reaction of post-execution modules like Behavioral Threat Protection, ransomware, NPI etc. Even if WF verdicts are benign, post-execution modules will continue to operate independently and can mitigate threats in-flight.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have any statistical data at hand - but again, it depends on the tenant configuration. Some organizations might have WF disabled, and thus, solely depend on Local Analysis verdicts. Verdicts can vary between industry verticals, types of software used, internet access control (air-gapped systems vs direct internet exposure), administrative rights of endpoint user, firewall configurations and the list goes on. So,&amp;nbsp;&lt;EM&gt;it depends!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please refer to this detailed documentation on Cortex XDR file analysis and protection flows:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/analysis-and-protection-flow.html#idc8514e04-490b-498a-b9ca-b68dfc5be3d4" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/analysis-and-protection-flow.html#idc8514e04-490b-498a-b9ca-b68dfc5be3d4&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 04:56:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-most-decisions-are-made-by-cortex-xdr/m-p/469984#M1600</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-03-03T04:56:09Z</dc:date>
    </item>
  </channel>
</rss>

