<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR blocks visual studio codes everytime in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocks-visual-studio-codes-everytime/m-p/512846#M2686</link>
    <description>&lt;P&gt;Hi Teja,&lt;BR /&gt;Have u found any way for this , we are also facing the same issue&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Aug 2022 14:25:05 GMT</pubDate>
    <dc:creator>Anil_Racharla</dc:creator>
    <dc:date>2022-08-24T14:25:05Z</dc:date>
    <item>
      <title>Cortex XDR blocks visual studio codes everytime</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocks-visual-studio-codes-everytime/m-p/447124#M1232</link>
      <description>&lt;P&gt;We have observed that cortex XDR always blocks the code written in microsoft visual studio. General codes in C language like Hello world and addtion of two numbers is also geeting blocked in local analysis and it takes a lot of time to get verdict from wildfire to allow it. Usually whenever developer is running in debug mode this issue is faced and in debug they need to frequently change codes and debug it. When i discussed with one of palo alto support techinicial he suggested to whitelist the workspace folders or add signature and allow it which is not feasible solution as workspace paths keep changing per systems and users.&amp;nbsp; Similar issue we observred for python codes also and after wildfire check that code shows as malware (false positive as many time when we report it as incorrect verdict gets changed).&lt;BR /&gt;&lt;BR /&gt;Is there anyone who also faces same issue and found solution on this please help on this.&amp;nbsp;&lt;BR /&gt;Thanks in advance.&lt;BR /&gt;&lt;BR /&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 05:38:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocks-visual-studio-codes-everytime/m-p/447124#M1232</guid>
      <dc:creator>tejasp04</dc:creator>
      <dc:date>2021-11-12T05:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR blocks visual studio codes everytime</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocks-visual-studio-codes-everytime/m-p/447214#M1233</link>
      <description>&lt;P&gt;Hi Tejasp04,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see here several things to do.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;You could report a wrong verdict from WF and in 24h it should be updated on our side. You will be notify back on an email about this.&lt;/LI&gt;&lt;/UL&gt;&lt;P class="lia-indent-padding-left-60px"&gt;Hint: From key artifacts of the incident/alert open the WF report and on the upper right corner you can click to report the incorrect WF verdict.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Add an exception like a Global Digital Signer Exception. Please check if any other exception described on this doc could help you for other scenarios:&lt;/LI&gt;&lt;/UL&gt;&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/exceptions-security-profiles/add-a-global-endpoint-policy-exception" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/exceptions-security-profiles/add-a-global-endpoint-policy-exception&lt;/A&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I believe that this doc will be more suited to your specific need "Add a New Malware Security Profile". Here you can add signers to your allow list. (STEP 3, read point 4).&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;I also paste down bellow how local analysis works and why the former should work (adding a signer to your allow list)&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV&gt;Local analysis&lt;/DIV&gt;—When an unknown executable, DLL, or macro attempts to run on a Windows or Mac endpoint, the Cortex XDR agent uses local analysis to determine if it is likely to be malware. On Windows endpoints, if the file is signed by a known signer, the Cortex XDR agent permits the file to run and does not perform additional analysis. For files on Mac endpoints and files that are not signed by a known signer on Windows endpoints, the Cortex XDR agent performs local analysis to determine whether the file is malware. Local analysis uses a static set of pattern-matching rules that inspect multiple file features and attributes, and a statistical model that was developed with machine learning on WildFire threat intelligence. The model enables the Cortex XDR agent to examine hundreds of characteristics for a file and issue a local verdict (benign or malicious) while the endpoint is offline or Cortex XDR is unreachable. The Cortex XDR agent can rely on the local analysis verdict until it receives an official WildFire verdict or hash exception.&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;Local analysis is enabled by default in a Malware Security profile. Because local analysis always returns a verdict for an unknown file, if you enable the Cortex XDR agent to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Block files with unknown verdict&lt;/SPAN&gt;, the agent only blocks unknown files if a local analysis error occurs or local analysis is disabled. To change the default settings (not recommended), see&amp;nbsp;&amp;nbsp;Add a New Malware Security Profile.&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;P&gt;I hope this helps&lt;/P&gt;&lt;P&gt;Good weekend,&lt;/P&gt;&lt;P&gt;Luis&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 14:50:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocks-visual-studio-codes-everytime/m-p/447214#M1233</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2021-11-12T14:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR blocks visual studio codes everytime</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocks-visual-studio-codes-everytime/m-p/449046#M1273</link>
      <description>&lt;P&gt;Hi Eluis,&lt;/P&gt;&lt;P&gt;Thanks for your reponse.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've checked above documents/article for exception profile and signer exception. But unfortunetly it didnt worked in my organization. As developer are creating exe by compiling the codes and running those directly, so signatures they are not addin g there and not required in there projects. For local analysis exception as checked visual code application is running/compiling that codes and geneating exe with powershell.exe process and creating exception for powershell.exe is not recommended in our org as it might lead to any other threat execution.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Very strange behaviour of XDR i observed when 1 developer was compiling and running code through visual code application. same code was generating diff hash valued exe every time so xdr was taking long time for analysis and it was in evaluation status for every time. So there are such case where user is frequenlty creating and running exe's and it not feasible every time to ask wildfire to recheck verdicts.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Is there anything which we can check more on this or creating exceptions is only way to resolve these issues.&lt;BR /&gt;&lt;BR /&gt;Thanks in advance&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 06:08:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocks-visual-studio-codes-everytime/m-p/449046#M1273</guid>
      <dc:creator>tejasp04</dc:creator>
      <dc:date>2021-11-23T06:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR blocks visual studio codes everytime</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocks-visual-studio-codes-everytime/m-p/449053#M1274</link>
      <description>&lt;P&gt;Hi Tejasp04,&lt;/P&gt;&lt;P&gt;in this case I could recommend opening a support ticket. It might be that you need a support exception for your specific scenario.&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this point I believe this is the best option, this should solve your issue.&lt;/P&gt;&lt;P&gt;KR,&lt;/P&gt;&lt;P&gt;Luis&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 07:59:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocks-visual-studio-codes-everytime/m-p/449053#M1274</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2021-11-23T07:59:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR blocks visual studio codes everytime</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocks-visual-studio-codes-everytime/m-p/512846#M2686</link>
      <description>&lt;P&gt;Hi Teja,&lt;BR /&gt;Have u found any way for this , we are also facing the same issue&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2022 14:25:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocks-visual-studio-codes-everytime/m-p/512846#M2686</guid>
      <dc:creator>Anil_Racharla</dc:creator>
      <dc:date>2022-08-24T14:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR blocks visual studio codes everytime</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocks-visual-studio-codes-everytime/m-p/512929#M2692</link>
      <description>&lt;P&gt;Hi Anil,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Discussed same with support team multiple times and they are only suggesting to add exception rules in profile for affected user.&lt;/P&gt;
&lt;P&gt;Adding Exceptipon profile worked in our case.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 03:56:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocks-visual-studio-codes-everytime/m-p/512929#M2692</guid>
      <dc:creator>tejasp04</dc:creator>
      <dc:date>2022-08-25T03:56:30Z</dc:date>
    </item>
  </channel>
</rss>

