<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Protection against Hack5 tools incl. USB Rubber Ducky in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/protection-against-hack5-tools-incl-usb-rubber-ducky/m-p/517336#M2985</link>
    <description>&lt;P&gt;Hello dear community,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone of you expierience with usb rubber ducky and cortex xdr?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our supplier couldn't answer this from the beginnen of the poc. (~1Y)&lt;/P&gt;
&lt;P&gt;Maybe the collection of a community like you get this question faster answered?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to know how cortex would stop it in a smart way.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
    <pubDate>Mon, 10 Oct 2022 17:48:14 GMT</pubDate>
    <dc:creator>Cyber1985</dc:creator>
    <dc:date>2022-10-10T17:48:14Z</dc:date>
    <item>
      <title>Protection against Hack5 tools incl. USB Rubber Ducky</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/protection-against-hack5-tools-incl-usb-rubber-ducky/m-p/517336#M2985</link>
      <description>&lt;P&gt;Hello dear community,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone of you expierience with usb rubber ducky and cortex xdr?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our supplier couldn't answer this from the beginnen of the poc. (~1Y)&lt;/P&gt;
&lt;P&gt;Maybe the collection of a community like you get this question faster answered?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to know how cortex would stop it in a smart way.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 17:48:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/protection-against-hack5-tools-incl-usb-rubber-ducky/m-p/517336#M2985</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-10-10T17:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: Protection against Hack5 tools incl. USB Rubber Ducky</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/protection-against-hack5-tools-incl-usb-rubber-ducky/m-p/517468#M3002</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Cyber1985,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;By default, all external USB devices are allowed to connect to Cortex XDR endpoints. However, you can use Cortex XDR to manage and block devices connecting to an endpoint using &lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/hardened-endpoint-security/device-control" target="_blank"&gt;&lt;SPAN&gt;Device Control.&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;After you apply Device Control rules in your environment, use the Endpoints -&amp;gt; Device Control Violations page to monitor all instances where end users attempted to connect restricted USB-connected devices and Cortex XDR blocked them on the endpoint.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;I would also advise you to go through &lt;/SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-device-control-blocks-mobile-hotspots-through/m-p/514837#M2814%20Turn%20on%20screen%20reader%20support%20%20https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-device-control-blocks-mobile-hotspots-through/m-p/514837#M2814" target="_blank"&gt;&lt;SPAN&gt;this thread&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;, which discusses how to create custom device classes.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Last, Cortex XDR should also be able to detect Rubber Duckies and similar devices((depending on the payload being executed) through its BTP module.&lt;BR /&gt;&lt;BR /&gt;Hope this helps!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 15:08:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/protection-against-hack5-tools-incl-usb-rubber-ducky/m-p/517468#M3002</guid>
      <dc:creator>mavraham</dc:creator>
      <dc:date>2022-10-11T15:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: Protection against Hack5 tools incl. USB Rubber Ducky</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/protection-against-hack5-tools-incl-usb-rubber-ducky/m-p/517688#M3012</link>
      <description>&lt;P&gt;From my expierience now on, it doesn't make sence to block HID Devices in cortex. Who does this? You would need to WL All the guids from All Keyboards in place.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;An it would be the same for RD, because this is also just a HID usb device.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 20:29:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/protection-against-hack5-tools-incl-usb-rubber-ducky/m-p/517688#M3012</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-10-12T20:29:56Z</dc:date>
    </item>
  </channel>
</rss>

