<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does Cortex XDR Device Control blocks mobile hotspots through USB? [PART 2] in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-device-control-blocks-mobile-hotspots-through/m-p/515956#M2905</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi Max,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Device Control instances under Endpoints &amp;gt; Device Control Violations monitor all attempts to connect &lt;/SPAN&gt;&lt;STRONG&gt;restricted&lt;/STRONG&gt;&lt;SPAN&gt; USB-connected devices to Cortex XDR. Because of this, your instances of device allowance will not appear in this output menu.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You are correct that the block would apply to all of the network adapters in Windows. With Device Control exceptions, you are able to create exceptions to this baseline block by adding your trusted network adapter connections.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Permanent/temporary exceptions for your network can be made under Endpoints &amp;gt; Policy Management &amp;gt; Extensions &amp;gt; Device Permanent/Temporary Exceptions. To tune exceptions for particular endpoints, this can be configured to your Device Exceptions profile under Endpoints &amp;gt; Policy Management &amp;gt; Extensions &amp;gt; Profiles.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mfakhouri_0-1664210698831.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44149i2EA53D5EFFFF3C0F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="mfakhouri_0-1664210698831.png" alt="mfakhouri_0-1664210698831.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Add your trusted device types here. Your custom network adapter type should come up under "custom device types". Add the corresponding vendor and product or serial number as well.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;After setting your device control policy to block network adapter connections, the configured devices should be exempt from the block.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Further reading:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/hardened-endpoint-security/device-control" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/hardened-endpoint-security/device-control&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 26 Sep 2022 17:09:30 GMT</pubDate>
    <dc:creator>mfakhouri</dc:creator>
    <dc:date>2022-09-26T17:09:30Z</dc:date>
    <item>
      <title>Does Cortex XDR Device Control blocks mobile hotspots through USB? [PART 2]</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-device-control-blocks-mobile-hotspots-through/m-p/515703#M2872</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;In my last post I was asking if Cortex XDR was able to block USB network connections and the answer was that by default not.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However thanks to the solution I was able to find a settings that lets you add a new device for device control module. This way I connected the smartphone via USB, started USB internet sharing and found the specific device.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="maksymilianjan_0-1663857995892.png" style="width: 540px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44083i08E4378E2922F9EE/image-dimensions/540x18/is-moderation-mode/true?v=v2" width="540" height="18" role="button" title="maksymilianjan_0-1663857995892.png" alt="maksymilianjan_0-1663857995892.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, to add this device in Cortex you need the GUID and add it as a new device:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="maksymilianjan_2-1663858118111.png" style="width: 294px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44085i97A3976385D471F0/image-dimensions/294x300/is-moderation-mode/true?v=v2" width="294" height="300" role="button" title="maksymilianjan_2-1663858118111.png" alt="maksymilianjan_2-1663858118111.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However this&amp;nbsp;4d36e972-e325-11ce-bfc1-08002be10318 GUID is the same for (i suspect) all of the network adapters in windows.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This way there is no ability to block *only* this behavior right? I configured the policy with this device for only "Allow" actions but no events were shown even after tests. Does the "allow" policy in cortex xdr device management works same as a report setting?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this is not possible, is there any other way to block this kind of connections through smartphones (or even other USB portable network adapters).&lt;BR /&gt;&lt;BR /&gt;Thanks!!&lt;BR /&gt;&lt;BR /&gt;Max&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 14:51:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-device-control-blocks-mobile-hotspots-through/m-p/515703#M2872</guid>
      <dc:creator>maksymilianjan</dc:creator>
      <dc:date>2022-09-22T14:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cortex XDR Device Control blocks mobile hotspots through USB? [PART 2]</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-device-control-blocks-mobile-hotspots-through/m-p/515956#M2905</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Max,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Device Control instances under Endpoints &amp;gt; Device Control Violations monitor all attempts to connect &lt;/SPAN&gt;&lt;STRONG&gt;restricted&lt;/STRONG&gt;&lt;SPAN&gt; USB-connected devices to Cortex XDR. Because of this, your instances of device allowance will not appear in this output menu.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You are correct that the block would apply to all of the network adapters in Windows. With Device Control exceptions, you are able to create exceptions to this baseline block by adding your trusted network adapter connections.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Permanent/temporary exceptions for your network can be made under Endpoints &amp;gt; Policy Management &amp;gt; Extensions &amp;gt; Device Permanent/Temporary Exceptions. To tune exceptions for particular endpoints, this can be configured to your Device Exceptions profile under Endpoints &amp;gt; Policy Management &amp;gt; Extensions &amp;gt; Profiles.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mfakhouri_0-1664210698831.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44149i2EA53D5EFFFF3C0F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="mfakhouri_0-1664210698831.png" alt="mfakhouri_0-1664210698831.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Add your trusted device types here. Your custom network adapter type should come up under "custom device types". Add the corresponding vendor and product or serial number as well.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;After setting your device control policy to block network adapter connections, the configured devices should be exempt from the block.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Further reading:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/hardened-endpoint-security/device-control" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/hardened-endpoint-security/device-control&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 17:09:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-device-control-blocks-mobile-hotspots-through/m-p/515956#M2905</guid>
      <dc:creator>mfakhouri</dc:creator>
      <dc:date>2022-09-26T17:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cortex XDR Device Control blocks mobile hotspots through USB? [PART 2]</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-device-control-blocks-mobile-hotspots-through/m-p/516167#M2913</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/222081"&gt;@maksymilianjan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Probably its not going to show in device control as its not considered as portable device or disk drive&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First try this XQL query if its shows :&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;preset = device_control&lt;BR /&gt;| fields agent_hostname as hostname, action_device_usb_product_name as product, &amp;nbsp;action_device_usb_vendor_name as vendor, action_device_usb_serial_&lt;WBR /&gt;number as serial_number&lt;BR /&gt;| dedup hostname, product, vendor, serial_number&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If it doesnt.. try this..then from result, you can explore and try to find the device.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;preset = xdr_registry&lt;BR /&gt;| filter agent_hostname="Hostname" // add hostname that usb was seen on here&lt;BR /&gt;| filter lowercase(action_registry_full_key) ~= "enum.*usb"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 05:40:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-device-control-blocks-mobile-hotspots-through/m-p/516167#M2913</guid>
      <dc:creator>jcandelaria</dc:creator>
      <dc:date>2022-09-28T05:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cortex XDR Device Control blocks mobile hotspots through USB? [PART 2]</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-device-control-blocks-mobile-hotspots-through/m-p/518510#M3038</link>
      <description>&lt;P&gt;Hey,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry for the late reply but this was a lifesaver as I did not know that XQL will show more events.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now there are devices like:&amp;nbsp;Galaxy series, misc. (tethering mode) which is just what I was looking for.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Also, just FYI I made this BIOC rule for detecting the activity via registry changes (needs some tuning):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;preset = xdr_registry &lt;BR /&gt;| filter (action_registry_key_name = """HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\usbrndis*\\Enum""") &lt;BR /&gt;| filter (action_registry_data contains """USB\\VID""")&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 11:39:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-device-control-blocks-mobile-hotspots-through/m-p/518510#M3038</guid>
      <dc:creator>maksymilianjan</dc:creator>
      <dc:date>2022-10-20T11:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cortex XDR Device Control blocks mobile hotspots through USB? [PART 2]</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-device-control-blocks-mobile-hotspots-through/m-p/540752#M4271</link>
      <description>&lt;P&gt;Is there any device control API endpoint to xdr cortex?&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 10:38:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-device-control-blocks-mobile-hotspots-through/m-p/540752#M4271</guid>
      <dc:creator>aaminahassan</dc:creator>
      <dc:date>2023-05-02T10:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cortex XDR Device Control blocks mobile hotspots through USB? [PART 2]</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-device-control-blocks-mobile-hotspots-through/m-p/540865#M4276</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/288862"&gt;@aaminahassan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did understood your question or ask, could you share your use case or example for your query? Is your ask for api to get list of device control violations? If yes, we do have api for that you may refer here&amp;nbsp;&lt;A href="https://cortex-panw.stoplight.io/docs/cortex-xdr/284c7d894406d-get-violations" target="_self"&gt;Get Violations&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 05:18:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-device-control-blocks-mobile-hotspots-through/m-p/540865#M4276</guid>
      <dc:creator>PiyushKohli</dc:creator>
      <dc:date>2023-05-03T05:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cortex XDR Device Control blocks mobile hotspots through USB? [PART 2]</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-device-control-blocks-mobile-hotspots-through/m-p/540867#M4278</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I want to&amp;nbsp; whitelist USB using&amp;nbsp; API call.&lt;BR /&gt;Under device control I can see only get_violations. I can get_violations of device but don't know the exact parameters/API end point to whitelist the device. like serial number /vendor etc to be used in which call?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 05:22:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-device-control-blocks-mobile-hotspots-through/m-p/540867#M4278</guid>
      <dc:creator>aaminahassan</dc:creator>
      <dc:date>2023-05-03T05:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cortex XDR Device Control blocks mobile hotspots through USB? [PART 2]</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-device-control-blocks-mobile-hotspots-through/m-p/541040#M4292</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/288862"&gt;@aaminahassan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently the only way to whitelist the device would be through UI under Device exceptions.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reference: &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Device-Control?section=UUID-213a05b7-fac8-8a21-8286-5818459654a9_idcf547473-46ef-485e-9b58-acf1e9f37097" target="_self"&gt;Device Control&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 10:29:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-device-control-blocks-mobile-hotspots-through/m-p/541040#M4292</guid>
      <dc:creator>PiyushKohli</dc:creator>
      <dc:date>2023-05-04T10:29:18Z</dc:date>
    </item>
  </channel>
</rss>

