<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: initial profiling? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/initial-profiling/m-p/344228#M252</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149855"&gt;@TonyTovar&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes. Prevent protects from malware, exploits, advanced threats.&amp;nbsp; It does not include the analytics and some of the other EDR features.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Aug 2020 18:40:01 GMT</pubDate>
    <dc:creator>dfalcon</dc:creator>
    <dc:date>2020-08-17T18:40:01Z</dc:date>
    <item>
      <title>initial profiling?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/initial-profiling/m-p/339965#M218</link>
      <description>&lt;P&gt;when you first install the Cortex XDR agent on a new server (and reboot if on Windows), is it immediately 'active' and blocking suspicious processes? I was told that it ran in 'passive' mode for 30-days as it built a profile of "normal" activity for that agent. I ask because we are starting to use immutable servers which are recreated from-scratch on a regular basis.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2020 23:23:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/initial-profiling/m-p/339965#M218</guid>
      <dc:creator>TonyTovar</dc:creator>
      <dc:date>2020-07-21T23:23:50Z</dc:date>
    </item>
    <item>
      <title>Re: initial profiling?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/initial-profiling/m-p/339968#M220</link>
      <description>&lt;P&gt;Hi there-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For malware, exploits, and most threats - those are blocked immediately based on your malware / exploit profile settings under the endpoint management section.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The profiling you are referencing refers to the analytics component. &amp;nbsp;That feature is essentially learning the behavior of the environment based on the computer and user entity. &amp;nbsp;It is learning who is supposed to be doing what — it raises an alert when suspicious behavior is detected based on the behavior not matching that entity. &amp;nbsp;The profiling ranges anywhere from a few days to 4 weeks based on the collector type.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 00:24:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/initial-profiling/m-p/339968#M220</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-07-22T00:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: initial profiling?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/initial-profiling/m-p/343953#M243</link>
      <description>&lt;P&gt;Thanks, David! So, in general, the agent is 'active' and protected the server immediately -- but with some delay for the "analytics" portion?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I have now learned that there are 3 Cortex XDR licenses and we probably have just the base license (not "Pro"). So we are not getting EUBA or Network-Traffic Analytics. Was one of those the 'analytics' module to which you were referring? Or, is there also such a module in the base license?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 20:48:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/initial-profiling/m-p/343953#M243</guid>
      <dc:creator>TonyTovar</dc:creator>
      <dc:date>2020-08-14T20:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: initial profiling?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/initial-profiling/m-p/344216#M249</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149855"&gt;@TonyTovar&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, that is correct.&amp;nbsp; If you are using Prevent, the profiling component is not part of that offering.&amp;nbsp; You have all included protections available immediately.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 17:20:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/initial-profiling/m-p/344216#M249</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-08-17T17:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: initial profiling?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/initial-profiling/m-p/344217#M250</link>
      <description>&lt;P&gt;Is 'Prevent' the base-level license?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 17:27:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/initial-profiling/m-p/344217#M250</guid>
      <dc:creator>TonyTovar</dc:creator>
      <dc:date>2020-08-17T17:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: initial profiling?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/initial-profiling/m-p/344228#M252</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149855"&gt;@TonyTovar&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes. Prevent protects from malware, exploits, advanced threats.&amp;nbsp; It does not include the analytics and some of the other EDR features.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 18:40:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/initial-profiling/m-p/344228#M252</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-08-17T18:40:01Z</dc:date>
    </item>
  </channel>
</rss>

