<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: When to use policy changes or alert exceptions in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/when-to-use-policy-changes-or-alert-exceptions/m-p/514385#M2790</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/224150"&gt;@Aiman_Fathima&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This indeed is a broad question as Cortex XDR umpteen number of malware alert categories that can trigger and those can be treated by using methodologies(exceptions and file path whitelists)in different used cases. I would suggest to kindly reach out to you Professional Services Consultant/Customer Success Architect or SE for detailed discussion on the same to outline the used cases and their recommended practice mechanisms.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Sep 2022 06:54:55 GMT</pubDate>
    <dc:creator>neelrohit</dc:creator>
    <dc:date>2022-09-09T06:54:55Z</dc:date>
    <item>
      <title>When to use policy changes or alert exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/when-to-use-policy-changes-or-alert-exceptions/m-p/514299#M2779</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When a BTP rule is blocking a process,&lt;/P&gt;
&lt;P&gt;When do we create a policy change and allow the process, and when do we create an alerts exception to allow the process.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 17:06:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/when-to-use-policy-changes-or-alert-exceptions/m-p/514299#M2779</guid>
      <dc:creator>Aiman_Fathima</dc:creator>
      <dc:date>2022-09-08T17:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: When to use policy changes or alert exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/when-to-use-policy-changes-or-alert-exceptions/m-p/514307#M2782</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/224150"&gt;@Aiman_Fathima&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reaching out to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When a BTP rule is blocking a process and you consider this activity as a false positive, you can create alert exception for the change without changing any configurations in the policy itself. Right click on the alert&amp;gt; Manage alert&amp;gt; Create Alert exception. You can choose a list of parameters by checking the boxes (like SHA256, signer, cgo, cgo cmdline params etc.) to make a logical granular condition. Choose the exception scope(&lt;STRONG&gt;profile&lt;/STRONG&gt; for specific set of endpoints using that profile in a policy or &lt;STRONG&gt;global&lt;/STRONG&gt; for all endpoints).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This in turn disables the rule within the BTP module triggering the alert and cripples it for the execution of parameters and endpoints you defined above. If this behaviour is expected for larger set of endpoints in your environment and not one off events, you can &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-endpoint-alerts/manage-alerts#:~:text=the%20following%20options%3A-,Retrieve%20alert%20data,-%E2%80%94Cortex%20XDR" target="_blank" rel="noopener"&gt;retrieve the alert data&lt;/A&gt; and please reach out to our &lt;A href="https://support.paloaltonetworks.com" target="_self"&gt;Palo Alto Networks Technical Assistance Center&lt;/A&gt; for content whitelisting or support based exceptions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once the engineering team determines the event as a false positive and globally applicable, they would release the fix in a content update and you can disable the alert exception created once you ensure your endpoints get the content version with the fix.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 17:55:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/when-to-use-policy-changes-or-alert-exceptions/m-p/514307#M2782</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2022-09-08T17:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: When to use policy changes or alert exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/when-to-use-policy-changes-or-alert-exceptions/m-p/514338#M2784</link>
      <description>&lt;P&gt;Hello Neelrohit,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for your information. Maybe this informations could find a way to the documentation with a nice cheat sheet?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are a little bit confused about the broad possibilites to exclude alerts, processes, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 21:01:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/when-to-use-policy-changes-or-alert-exceptions/m-p/514338#M2784</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-09-08T21:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: When to use policy changes or alert exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/when-to-use-policy-changes-or-alert-exceptions/m-p/514370#M2787</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi, &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks for the clarification.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Could you please give us more idea about when to use "Malware" profile based whitelisting and when to use "Exception" profile based whitelisting.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 06:19:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/when-to-use-policy-changes-or-alert-exceptions/m-p/514370#M2787</guid>
      <dc:creator>Aiman_Fathima</dc:creator>
      <dc:date>2022-09-09T06:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: When to use policy changes or alert exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/when-to-use-policy-changes-or-alert-exceptions/m-p/514385#M2790</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/224150"&gt;@Aiman_Fathima&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This indeed is a broad question as Cortex XDR umpteen number of malware alert categories that can trigger and those can be treated by using methodologies(exceptions and file path whitelists)in different used cases. I would suggest to kindly reach out to you Professional Services Consultant/Customer Success Architect or SE for detailed discussion on the same to outline the used cases and their recommended practice mechanisms.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 06:54:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/when-to-use-policy-changes-or-alert-exceptions/m-p/514385#M2790</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2022-09-09T06:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: When to use policy changes or alert exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/when-to-use-policy-changes-or-alert-exceptions/m-p/514387#M2791</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out to us and for your suggestions! Please see my response below to the question. We will try to see if that is possible or not as exposing operations mechanisms for security tool on open forum could turn out to be a security issue. However, we will try our best for future line up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For now I would recommend to kindly reach out to you Professional Services Consultant/Customer Success Team/ SE for the same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 06:58:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/when-to-use-policy-changes-or-alert-exceptions/m-p/514387#M2791</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2022-09-09T06:58:00Z</dc:date>
    </item>
  </channel>
</rss>

