<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Microsoft SQL Server exceptions/exclusions in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/microsoft-sql-server-exceptions-exclusions/m-p/515730#M2877</link>
    <description>&lt;P&gt;Hello dear community,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how do you handle MSSQL Server exceptions/exclusions with Cortex XDR (Pro)?&lt;/P&gt;
&lt;P&gt;Are there any issues a MSSQL Server with two or more instances with more than 5 databases?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any vendor specific recommendation?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Sep 2022 18:28:50 GMT</pubDate>
    <dc:creator>RFeyertag</dc:creator>
    <dc:date>2022-09-22T18:28:50Z</dc:date>
    <item>
      <title>Microsoft SQL Server exceptions/exclusions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/microsoft-sql-server-exceptions-exclusions/m-p/515730#M2877</link>
      <description>&lt;P&gt;Hello dear community,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how do you handle MSSQL Server exceptions/exclusions with Cortex XDR (Pro)?&lt;/P&gt;
&lt;P&gt;Are there any issues a MSSQL Server with two or more instances with more than 5 databases?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any vendor specific recommendation?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 18:28:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/microsoft-sql-server-exceptions-exclusions/m-p/515730#M2877</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-09-22T18:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft SQL Server exceptions/exclusions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/microsoft-sql-server-exceptions-exclusions/m-p/515961#M2906</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Rob,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When any process is launched, Cortex XDR seamlessly inserts agent inject libraries immediately after the operating system initiates a process created. Please refer to the following model:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mfakhouri_0-1664213084010.png" style="width: 759px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44151i7394411DE1FA8D17/image-dimensions/759x186/is-moderation-mode/true?v=v2" width="759" height="186" role="button" title="mfakhouri_0-1664213084010.png" alt="mfakhouri_0-1664213084010.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Exceptions can disable any relevant exploit modules configured with the agent that is running MSSQL and can be found in Policy Management &amp;gt; Prevention Profiles &amp;gt; Create new profile or edit existing profile for exceptions &amp;gt; Process exceptions. With the case of the model demonstrated, this would require an exception to disable injections. However, an accurate deployment for your needs would vary depending on your existing configuration. The “Select Modules” dropdown will list all available exploit protection modules that you would like to create an exception for from your baseline policy.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mfakhouri_1-1664213084027.png" style="width: 608px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44152iB8DE56B5EAF3C57C/image-dimensions/608x450/is-moderation-mode/true?v=v2" width="608" height="450" role="button" title="mfakhouri_1-1664213084027.png" alt="mfakhouri_1-1664213084027.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also, exclusions function differently than exceptions. Exclusions will suppress a subset of defined alerts from Cortex XDR. This can be configured in Incident Response &amp;gt; Incident Configuration &amp;gt; Alert Exclusions. You can explore around with alert filtering if you would like to suppress MSSQL related alerts from specific endpoints. For additional details, please refer to the documentation posted below.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am unable to confirm/deny any documented issues regarding running a MSSQL Server with two or more instances running more than 5 databases alongside the agent. This would likely vary based on your available computing resources. If you do happen to run into any issues with running the agent alongside your MSSQL database instances, we highly recommend contacting our TAC team at support.paloaltonetworks.com&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Finally, there are no particular recommendations for any specific vendor. If you are looking to integrate a database connection to directly query from Cortex XDR, the Database Collector supports the MySQL, PostgreSQL, MSSQL, and Oracle connection types.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;References:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Exceptions:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/exceptions-security-profiles" target="_blank"&gt;&lt;SPAN&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/exceptions-security-profiles&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Exclusions:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-endpoint-alerts/alert-exclusions" target="_blank"&gt;&lt;SPAN&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-endpoint-alerts/alert-exclusions&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Configure the Database Collector:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/broker-vm/set-up-broker-vm/activate-the-database-collector" target="_blank"&gt;&lt;SPAN&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/broker-vm/set-up-broker-vm/activate-the-database-collector&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 17:42:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/microsoft-sql-server-exceptions-exclusions/m-p/515961#M2906</guid>
      <dc:creator>mfakhouri</dc:creator>
      <dc:date>2022-09-26T17:42:39Z</dc:date>
    </item>
  </channel>
</rss>

