<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic prevent exe application to install in a system via cortex xdr agent in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/346385#M265</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we prevent any .exe for e.g. anydesk application for installation in a system if the cortex XDR agent is installed, if it does how to configure it?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Sep 2020 09:23:56 GMT</pubDate>
    <dc:creator>OsamaKhan</dc:creator>
    <dc:date>2020-09-02T09:23:56Z</dc:date>
    <item>
      <title>prevent exe application to install in a system via cortex xdr agent</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/346385#M265</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we prevent any .exe for e.g. anydesk application for installation in a system if the cortex XDR agent is installed, if it does how to configure it?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2020 09:23:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/346385#M265</guid>
      <dc:creator>OsamaKhan</dc:creator>
      <dc:date>2020-09-02T09:23:56Z</dc:date>
    </item>
    <item>
      <title>Re: prevent exe application to install in a system via cortex xdr agent</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/348826#M289</link>
      <description>&lt;P&gt;I see two ways of accomplishing this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. You can configure your restriction policy by specifying something like *\&amp;lt;name_of_file&amp;gt;&amp;nbsp; &amp;nbsp;in the Executable Files section -&amp;gt; Files / Folders in Block List.&lt;/P&gt;&lt;P&gt;2. You can create a BIOC Rule that targets that process and apply it to Restriction policy:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xdr-indicators/working-with-biocs/create-a-bioc-rule.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xdr-indicators/working-with-biocs/create-a-bioc-rule.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best,&lt;/P&gt;&lt;P&gt;D&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Sep 2020 17:46:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/348826#M289</guid>
      <dc:creator>DKasabji</dc:creator>
      <dc:date>2020-09-13T17:46:17Z</dc:date>
    </item>
    <item>
      <title>Re: prevent exe application to install in a system via cortex xdr agent</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/349382#M306</link>
      <description>&lt;P&gt;I was hoping to do this with Cortex-XDR Prevent by blocking programs from running from the user profile, but the hashes change too often. I was hoping we could block everything from running and then allow some signed applications to run from the user profile.&amp;nbsp; I have had AppLocker on the list for some time to learn about.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 14:52:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/349382#M306</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-09-15T14:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: prevent exe application to install in a system via cortex xdr agent</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/349396#M307</link>
      <description>&lt;P&gt;For what you just described, I indeed would favor AppLocked approach, since it is designed to perform this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure about specifics of XDR Prevent, probably does not have all the capabilities that Pro Per Endpoint or Pro Per TB editions, but don't you have in your XDR Interface the option to configure 'Restrictions Profile'? It is in Endpoints -&amp;gt; Policy Management -&amp;gt; Profiles. You locate the Restrictions profile and Edit it.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;There you will find Executable Files paragraph where it asks you to input Files / FOLDERS in BLOCK LIST or in ALLOW LIST. So perhaps you could leverage this to specify that any executable within %USERPROFILE% is on BLOCK LIST.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Is that not possible in XDR Prevent?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best,&lt;/P&gt;&lt;P&gt;D&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 15:15:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/349396#M307</guid>
      <dc:creator>DKasabji</dc:creator>
      <dc:date>2020-09-15T15:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: prevent exe application to install in a system via cortex xdr agent</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/349397#M308</link>
      <description>&lt;P&gt;Forgot to add before:&lt;BR /&gt;I think the Block-listing approach is probably not the best, because I haven't tested the combination of Blocking everything in a specified folder, but then allowing a specific .EXE to run in that same folder. Not sure what takes precedence: does XDR first check the allowed list and then moves on to check the block list or vice versa.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, maybe you could configure it in a Allow-list approach by defining a Folder where you would allow the executables to run and everything else is blocked. But probably that is a bit to cumbersome to manage for end-users. Or even specific Files, which is (I think) similar to AppLocker approach.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 15:19:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/349397#M308</guid>
      <dc:creator>DKasabji</dc:creator>
      <dc:date>2020-09-15T15:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: prevent exe application to install in a system via cortex xdr agent</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/349513#M313</link>
      <description>&lt;P&gt;Yes, Cortex XDR Prevent's Restrictions profile works as you described -- I tested the setup last week.&amp;nbsp; The issue is that it is a maintenance nightmare...it was not really designed with this in mind.&amp;nbsp; You can stop all .EXE files from running from the user profile, but to allow some to run is based on the filename/hash.&amp;nbsp; AppLocker should allow me to setup things so that .EXE files signed by GotoMeeting are allowed, but not others. Oh, and Microsoft keeps stuffing Office 365 stuff under the user profile like Teams, OneDrive, etc.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 21:24:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/349513#M313</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-09-15T21:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: prevent exe application to install in a system via cortex xdr agent</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/349715#M317</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;@Retired Member&amp;nbsp;Hm. Then the last thing that comes to mind is to create a Prevention BIOC rule which you can apply to Restriction Profile.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You'd create a BIOC something like:&lt;BR /&gt;Process name: *.exe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Path: %USERPROFILE% (and any other path you want to prevent EXEs to not run)&lt;/P&gt;&lt;P&gt;Signature: SIGNED&lt;/P&gt;&lt;P&gt;Signer: NOT 'GoToMeetings' (etc.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then you set it in Restriction Profile as the Prevention Rule. This means that everytime an EXE process will execute that is in %USERPROFILE% and it is NOT signed by GoToMettings --&amp;gt; block the execution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe this could help you. But if you already decided on AppLocker, then never mind.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best,&lt;/P&gt;&lt;P&gt;D&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 06:25:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/349715#M317</guid>
      <dc:creator>DKasabji</dc:creator>
      <dc:date>2020-09-16T06:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: prevent exe application to install in a system via cortex xdr agent</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/349716#M318</link>
      <description>&lt;P&gt;OH crap! I forgot. The 'Prevent' license probably does not have the option to create BIOCs? Have no experience with Prevent license type, my bad.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 06:27:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/349716#M318</guid>
      <dc:creator>DKasabji</dc:creator>
      <dc:date>2020-09-16T06:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: prevent exe application to install in a system via cortex xdr agent</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/350217#M321</link>
      <description>&lt;P&gt;I appreciate the info - Pro was way outside of our budget.&amp;nbsp; I thought for a moment I had overlooked something (and the Palo Alto person who helped with the PoC didn't share this) so it nice to get confirmation I should not see the BIOC options on the web console.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 19:45:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/350217#M321</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-09-17T19:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: prevent exe application to install in a system via cortex xdr agent</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/351724#M336</link>
      <description>&lt;P&gt;Thanks for the update and quick reply. I'll be sure to keep an eye on this thread &lt;A href="https://www.dqfansurvey.org/" target="_self"&gt;&lt;FONT color="#333333"&gt;dqfansurvey&lt;/FONT&gt;&lt;/A&gt;&lt;FONT color="#333333"&gt;.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 11:48:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/prevent-exe-application-to-install-in-a-system-via-cortex-xdr/m-p/351724#M336</guid>
      <dc:creator>JosephNil</dc:creator>
      <dc:date>2020-09-24T11:48:36Z</dc:date>
    </item>
  </channel>
</rss>

