<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New to Cortex - Whitelisting files/paths, are they needed in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/new-to-cortex-whitelisting-files-paths-are-they-needed/m-p/517338#M2987</link>
    <description>&lt;P&gt;I would also be interested, if this Feature from Cortex xdr pro is comparable to applocker.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
    <pubDate>Mon, 10 Oct 2022 17:55:51 GMT</pubDate>
    <dc:creator>Cyber1985</dc:creator>
    <dc:date>2022-10-10T17:55:51Z</dc:date>
    <item>
      <title>New to Cortex - Whitelisting files/paths, are they needed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/new-to-cortex-whitelisting-files-paths-are-they-needed/m-p/517289#M2980</link>
      <description>&lt;P&gt;I am looking for definitive answers on whether or not exe files should be whitelisted and where they should be whitelisted within Cortex?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 12:20:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/new-to-cortex-whitelisting-files-paths-are-they-needed/m-p/517289#M2980</guid>
      <dc:creator>jeperjes</dc:creator>
      <dc:date>2022-10-10T12:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: New to Cortex - Whitelisting files/paths, are they needed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/new-to-cortex-whitelisting-files-paths-are-they-needed/m-p/517304#M2981</link>
      <description>&lt;P&gt;the files to be excluded are known windows files.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 13:57:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/new-to-cortex-whitelisting-files-paths-are-they-needed/m-p/517304#M2981</guid>
      <dc:creator>jeperjes</dc:creator>
      <dc:date>2022-10-10T13:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: New to Cortex - Whitelisting files/paths, are they needed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/new-to-cortex-whitelisting-files-paths-are-they-needed/m-p/517337#M2986</link>
      <description>&lt;P&gt;Maybe palo alto could bringt out a short Video for white and blacklisting paths/files?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 17:52:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/new-to-cortex-whitelisting-files-paths-are-they-needed/m-p/517337#M2986</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-10-10T17:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: New to Cortex - Whitelisting files/paths, are they needed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/new-to-cortex-whitelisting-files-paths-are-they-needed/m-p/517338#M2987</link>
      <description>&lt;P&gt;I would also be interested, if this Feature from Cortex xdr pro is comparable to applocker.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 17:55:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/new-to-cortex-whitelisting-files-paths-are-they-needed/m-p/517338#M2987</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-10-10T17:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: New to Cortex - Whitelisting files/paths, are they needed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/new-to-cortex-whitelisting-files-paths-are-they-needed/m-p/517383#M2992</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/242931"&gt;@jeperjes&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206384"&gt;@Cyber1985&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It likely depends on the used cases on what should be whitelisted. Definitely the easiest, quickest and the best whitelisted always is SH256 allow list, which is granular in itself. However, as iterated, when it comes to whitelisting executables, it would depend upon the business used case and alerts around it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Windows executables are microsoft signed application executables and because Microsoft is a highly trusted signer, Cortex XDR does not detect and examine it in the pre-exection stages(like Wildfire malware, Local Analysis).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the post execution stages, everything is examined as it leverages behavioral execution monitoring for script based, fileless attacks and exploitation events as well.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We also have a process exception which has the capability to disable select protection modules for Cortex XDR depending upon the choices and used cases.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please be apprised all of the above, will be specific to targets and profiles and should be implemented very carefully&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 01:32:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/new-to-cortex-whitelisting-files-paths-are-they-needed/m-p/517383#M2992</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2022-10-11T01:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: New to Cortex - Whitelisting files/paths, are they needed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/new-to-cortex-whitelisting-files-paths-are-they-needed/m-p/517640#M3009</link>
      <description>what is the right way to enter *.exe files into whitelists, or find the&lt;BR /&gt;hash of a file and add that to the whitelist?  What is the right way to&lt;BR /&gt;handle files to whitelist to avoid malicious files attacking a server?  I&lt;BR /&gt;am not familiar with the cortex and how they handle malwares.&lt;BR /&gt;</description>
      <pubDate>Wed, 12 Oct 2022 15:52:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/new-to-cortex-whitelisting-files-paths-are-they-needed/m-p/517640#M3009</guid>
      <dc:creator>jeperjes</dc:creator>
      <dc:date>2022-10-12T15:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: New to Cortex - Whitelisting files/paths, are they needed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/new-to-cortex-whitelisting-files-paths-are-they-needed/m-p/592826#M6989</link>
      <description>&lt;P&gt;yes they should.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 19:40:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/new-to-cortex-whitelisting-files-paths-are-they-needed/m-p/592826#M6989</guid>
      <dc:creator>jeperjes</dc:creator>
      <dc:date>2024-07-23T19:40:14Z</dc:date>
    </item>
  </channel>
</rss>

