<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex blocking hashes in allowed list in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-blocking-hashes-in-allowed-list/m-p/495152#M2058</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/204243"&gt;@MartinPfeil&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can also tweak wildfire verdict if you dont agree with it, and you will get an answer from us in 2 or 3 days.&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR,&lt;BR /&gt;Luis&lt;/P&gt;</description>
    <pubDate>Tue, 31 May 2022 09:05:15 GMT</pubDate>
    <dc:creator>eluis</dc:creator>
    <dc:date>2022-05-31T09:05:15Z</dc:date>
    <item>
      <title>Cortex blocking hashes in allowed list</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-blocking-hashes-in-allowed-list/m-p/493724#M2036</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just wondering why does cortex block hashes that are already part of allow list sometimes ?&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 15:48:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-blocking-hashes-in-allowed-list/m-p/493724#M2036</guid>
      <dc:creator>NivedaR</dc:creator>
      <dc:date>2022-05-27T15:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex blocking hashes in allowed list</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-blocking-hashes-in-allowed-list/m-p/493993#M2041</link>
      <description>&lt;P&gt;Hello! I had a similar problem with some incidents. I created the white listing, but the process still blocked.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The workaround was to restart the pc (and maybe to check in).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try it and give ma feedback if it is working for you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 21:31:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-blocking-hashes-in-allowed-list/m-p/493993#M2041</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-05-27T21:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex blocking hashes in allowed list</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-blocking-hashes-in-allowed-list/m-p/494470#M2049</link>
      <description>&lt;P&gt;Hello ! Thanks a ton for the workaround ! This is only working on few of the system.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 05:50:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-blocking-hashes-in-allowed-list/m-p/494470#M2049</guid>
      <dc:creator>NivedaR</dc:creator>
      <dc:date>2022-05-30T05:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex blocking hashes in allowed list</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-blocking-hashes-in-allowed-list/m-p/494511#M2050</link>
      <description>&lt;P&gt;We have similar problems with white-listed binaries and received the following explanation: The white listing only adds the hash to a list of static IOC, if the binary acts in a suspicious way (either live or in WildFire) it will be blocked. One solution is to always run the latest version and report false positives, the other one is creating a malware profile which excludes certain files and folders from being scanned.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 07:45:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-blocking-hashes-in-allowed-list/m-p/494511#M2050</guid>
      <dc:creator>MartinPfeil</dc:creator>
      <dc:date>2022-05-30T07:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex blocking hashes in allowed list</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-blocking-hashes-in-allowed-list/m-p/495152#M2058</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/204243"&gt;@MartinPfeil&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can also tweak wildfire verdict if you dont agree with it, and you will get an answer from us in 2 or 3 days.&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR,&lt;BR /&gt;Luis&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 09:05:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-blocking-hashes-in-allowed-list/m-p/495152#M2058</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2022-05-31T09:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex blocking hashes in allowed list</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-blocking-hashes-in-allowed-list/m-p/495166#M2060</link>
      <description>&lt;P&gt;Hello Eluis, this is a standard procedure when we identify false positive alerts: report an incorrect verdict back to Palo Alto. Unfortunatly we still have to deal with the results of the initial false positive detection, e.g. messed up and incomplete software installations and updates because WF blocked access to certain files on several systems. This happens especially with software development tools and foreign language software, especially Chinese.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 09:20:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-blocking-hashes-in-allowed-list/m-p/495166#M2060</guid>
      <dc:creator>MartinPfeil</dc:creator>
      <dc:date>2022-05-31T09:20:37Z</dc:date>
    </item>
  </channel>
</rss>

