<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Excluding files from local malware analysis scan in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/excluding-files-from-local-malware-analysis-scan/m-p/477757#M1825</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/196640"&gt;@Daniel_Itenberg&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;have you thought of adding the signer as a trusted signer ? this will not take into account the hash. This is useful also for drivers from specific vendors that sign their software.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check this doc on how to do it at the malware profile:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/endpoint-security-profiles/add-malware-security-profile.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/endpoint-security-profiles/add-malware-security-profile.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I wont recommend much to add a whole folder to the allow list since malicious actors might drop their malware there and go undetected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If hash and trusted signer do not work either of them, open a TAC support case to get a suex.&amp;nbsp;&lt;BR /&gt;Hope this helps&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luis&lt;/P&gt;</description>
    <pubDate>Sun, 03 Apr 2022 14:55:35 GMT</pubDate>
    <dc:creator>eluis</dc:creator>
    <dc:date>2022-04-03T14:55:35Z</dc:date>
    <item>
      <title>Excluding files from local malware analysis scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/excluding-files-from-local-malware-analysis-scan/m-p/477745#M1823</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have a specific file that i would like to whitelist. I have it in the allow list(by hash) but it still sometimes blocked by the "local analysis malware" due to having a different hash than the one in the allow list.&lt;/P&gt;&lt;P&gt;Is there a way to exclude a file from the scan via name, or any other way?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Apr 2022 07:11:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/excluding-files-from-local-malware-analysis-scan/m-p/477745#M1823</guid>
      <dc:creator>Daniel_Itenberg</dc:creator>
      <dc:date>2022-04-03T07:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding files from local malware analysis scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/excluding-files-from-local-malware-analysis-scan/m-p/477757#M1825</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/196640"&gt;@Daniel_Itenberg&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;have you thought of adding the signer as a trusted signer ? this will not take into account the hash. This is useful also for drivers from specific vendors that sign their software.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check this doc on how to do it at the malware profile:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/endpoint-security-profiles/add-malware-security-profile.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/endpoint-security-profiles/add-malware-security-profile.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I wont recommend much to add a whole folder to the allow list since malicious actors might drop their malware there and go undetected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If hash and trusted signer do not work either of them, open a TAC support case to get a suex.&amp;nbsp;&lt;BR /&gt;Hope this helps&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luis&lt;/P&gt;</description>
      <pubDate>Sun, 03 Apr 2022 14:55:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/excluding-files-from-local-malware-analysis-scan/m-p/477757#M1825</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2022-04-03T14:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding files from local malware analysis scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/excluding-files-from-local-malware-analysis-scan/m-p/477887#M1830</link>
      <description>&lt;P&gt;What if the signature filed says "invalid signature"?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 09:11:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/excluding-files-from-local-malware-analysis-scan/m-p/477887#M1830</guid>
      <dc:creator>Daniel_Itenberg</dc:creator>
      <dc:date>2022-04-04T09:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding files from local malware analysis scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/excluding-files-from-local-malware-analysis-scan/m-p/477909#M1831</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/196640"&gt;@Daniel_Itenberg&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would open a TAC support case to see what is the issue here. Our TAC engineers will provide you help on this&lt;/P&gt;&lt;P&gt;KR,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luis&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 10:10:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/excluding-files-from-local-malware-analysis-scan/m-p/477909#M1831</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2022-04-04T10:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding files from local malware analysis scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/excluding-files-from-local-malware-analysis-scan/m-p/477970#M1833</link>
      <description>&lt;P&gt;If the file is always in the same location you can create a malware profile and exclude this location from scanning.&lt;/P&gt;&lt;P&gt;That is the easiest solution, as chaning hashes will invalidate the entires in the allow list&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 14:36:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/excluding-files-from-local-malware-analysis-scan/m-p/477970#M1833</guid>
      <dc:creator>MartinPfeil</dc:creator>
      <dc:date>2022-04-04T14:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding files from local malware analysis scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/excluding-files-from-local-malware-analysis-scan/m-p/512944#M2693</link>
      <description>&lt;P&gt;Hii Eluis,&lt;BR /&gt;How to add a trusted signer .&lt;BR /&gt;How to sign a application which is internal built for organisation&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 05:42:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/excluding-files-from-local-malware-analysis-scan/m-p/512944#M2693</guid>
      <dc:creator>Anil_Racharla</dc:creator>
      <dc:date>2022-08-25T05:42:16Z</dc:date>
    </item>
  </channel>
</rss>

