<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Prevent Specific Questions in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-specific-questions/m-p/470700#M1609</link>
    <description>&lt;P&gt;Since this is a&amp;nbsp;Behavioral Threat , you may consider to "Add a Global Behavioral Threat Protection (BTP) Rule Exception" if this is what you are trying to accomplish, more details can be found in here &amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/exceptions-security-profiles/add-a-global-endpoint-policy-exception.html#:~:text=rules%20and%20policies.-,Add%20a%20Global%20Behavioral%20Threat%20Protection%20(BTP)%20Rule%20Exception,-When%20you%20view" target="_self"&gt;Add a Global Endpoint Policy Exception,&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This will take you to the below steps:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zarnous_0-1646500454033.png" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39499i05EA9271B924C0E0/image-dimensions/640x208/is-moderation-mode/true?v=v2" width="640" height="208" role="button" title="zarnous_0-1646500454033.png" alt="zarnous_0-1646500454033.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rather than creating global BTP rule exception, if you wish&amp;nbsp;To configure module specific exceptions relevant for the selected profile platform, you still can do for the module you choose, which is in your case BTP and limit the scope to a specific profile as below:&lt;BR /&gt;&lt;BR /&gt;Behavioral Threat Protection Rule Exception—When you view an alert for a Behavioral Threat event which you want to allow in your network from now on,&lt;BR /&gt;&lt;BR /&gt;1- Right-click the alert and Create alert exception.&lt;BR /&gt;2- Cortex XDR displays the alert data (Platform and Rule name).&lt;BR /&gt;3- Select Exception Scope: Profile and select the exception profile name. Click Add.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Link for the above -&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/exceptions-security-profiles/add-exceptions-profile.html#:~:text=Behavioral%20Threat%20Protection%20Rule%20Exception" target="_self"&gt;configure module specific exceptions&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Sat, 05 Mar 2022 17:21:32 GMT</pubDate>
    <dc:creator>zarnous</dc:creator>
    <dc:date>2022-03-05T17:21:32Z</dc:date>
    <item>
      <title>Cortex XDR Prevent Specific Questions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-specific-questions/m-p/470522#M1607</link>
      <description>&lt;P&gt;We are using Cortex XDR Prevent&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) I see many places the word 'rules' and 'rule exception' is used , I assume this option or feature is not available in Cortex XDR Prevent as I do not see it in the menus/blades .I guess its a 'Pro' edition feature . Please correct me .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) In Cortex XDR Prevent , I had a legitimate batch file which was 'prevented' by Cortex , so I was looking at best way to allow it to run on the host next time , so I added all hashes from ' Key Assets and Artifacts ' for the Incident to Allow list . So fingers crossed . However I see I get one option when I right click on the individual alert ' Create Alert Exception ' , I did not find any documentation about this feature in the pdf admin guide&amp;nbsp; , can anybody explain what this does and is this a better option . The alert source is ' XDR Agent ' and its a 'Behavioural threat '&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 13:19:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-specific-questions/m-p/470522#M1607</guid>
      <dc:creator>Balaraju</dc:creator>
      <dc:date>2022-03-04T13:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Prevent Specific Questions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-specific-questions/m-p/470700#M1609</link>
      <description>&lt;P&gt;Since this is a&amp;nbsp;Behavioral Threat , you may consider to "Add a Global Behavioral Threat Protection (BTP) Rule Exception" if this is what you are trying to accomplish, more details can be found in here &amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/exceptions-security-profiles/add-a-global-endpoint-policy-exception.html#:~:text=rules%20and%20policies.-,Add%20a%20Global%20Behavioral%20Threat%20Protection%20(BTP)%20Rule%20Exception,-When%20you%20view" target="_self"&gt;Add a Global Endpoint Policy Exception,&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This will take you to the below steps:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zarnous_0-1646500454033.png" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39499i05EA9271B924C0E0/image-dimensions/640x208/is-moderation-mode/true?v=v2" width="640" height="208" role="button" title="zarnous_0-1646500454033.png" alt="zarnous_0-1646500454033.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rather than creating global BTP rule exception, if you wish&amp;nbsp;To configure module specific exceptions relevant for the selected profile platform, you still can do for the module you choose, which is in your case BTP and limit the scope to a specific profile as below:&lt;BR /&gt;&lt;BR /&gt;Behavioral Threat Protection Rule Exception—When you view an alert for a Behavioral Threat event which you want to allow in your network from now on,&lt;BR /&gt;&lt;BR /&gt;1- Right-click the alert and Create alert exception.&lt;BR /&gt;2- Cortex XDR displays the alert data (Platform and Rule name).&lt;BR /&gt;3- Select Exception Scope: Profile and select the exception profile name. Click Add.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Link for the above -&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/exceptions-security-profiles/add-exceptions-profile.html#:~:text=Behavioral%20Threat%20Protection%20Rule%20Exception" target="_self"&gt;configure module specific exceptions&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 05 Mar 2022 17:21:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-specific-questions/m-p/470700#M1609</guid>
      <dc:creator>zarnous</dc:creator>
      <dc:date>2022-03-05T17:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Prevent Specific Questions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-specific-questions/m-p/470716#M1611</link>
      <description>&lt;P&gt;Thanks a lot for your response , this is very useful and thanks for all the explanation and URL Links .Appreciate it .&lt;/P&gt;</description>
      <pubDate>Sat, 05 Mar 2022 17:57:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-specific-questions/m-p/470716#M1611</guid>
      <dc:creator>Balaraju</dc:creator>
      <dc:date>2022-03-05T17:57:13Z</dc:date>
    </item>
  </channel>
</rss>

