<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr/m-p/523671#M3237</link>
    <description>&lt;P&gt;Hi people,&lt;/P&gt;
&lt;P&gt;1) I have installed the cortex XDR on end user PC and when I tried to scan email attachment on the end user PC I am not able to see any option to scan email attachment. I am a system Admin and I want the end user to scan email attachment with cortex. At present I have to download the attachment and do scan with cortex. I don't want to download this email attachment and scan the attachment whole without download. Any suggestion how can I make this scan with cortex comes when I right click on email attachment please.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) How can I block and allow USB drive from Cortex management portal?&lt;/P&gt;</description>
    <pubDate>Thu, 08 Dec 2022 23:47:31 GMT</pubDate>
    <dc:creator>lprasad</dc:creator>
    <dc:date>2022-12-08T23:47:31Z</dc:date>
    <item>
      <title>Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr/m-p/523671#M3237</link>
      <description>&lt;P&gt;Hi people,&lt;/P&gt;
&lt;P&gt;1) I have installed the cortex XDR on end user PC and when I tried to scan email attachment on the end user PC I am not able to see any option to scan email attachment. I am a system Admin and I want the end user to scan email attachment with cortex. At present I have to download the attachment and do scan with cortex. I don't want to download this email attachment and scan the attachment whole without download. Any suggestion how can I make this scan with cortex comes when I right click on email attachment please.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) How can I block and allow USB drive from Cortex management portal?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 23:47:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr/m-p/523671#M3237</guid>
      <dc:creator>lprasad</dc:creator>
      <dc:date>2022-12-08T23:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr/m-p/523705#M3240</link>
      <description>&lt;P&gt;Hello prasad.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you aim is to block USB drive, you can configure that by creating a agent setting policy in the policy management pane.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Go to endpoint--&amp;gt;policy management --&amp;gt; choose your OS--&amp;gt;Agent settings--&amp;gt; Agent security.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 13:39:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr/m-p/523705#M3240</guid>
      <dc:creator>NagaVenkatesh</dc:creator>
      <dc:date>2022-12-09T13:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr/m-p/523712#M3242</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/256014"&gt;@lprasad&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would disagree with &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/219216"&gt;@NagaVenkatesh&lt;/a&gt; answer. Agent settings profile is generally defining XDR agent behavior (GUI interface, agent auto update, disk quota etc). Agent Security specifically define agent tampering protection - protect files, folders and processes used by the XDR agent from unauthorized modification or even opening/reading.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With Agent settings profile -&amp;gt; User interface you can define if end user will have the option for "scan with cortex xdr" when right click on a file (basically allowing on-demand file scan by end user).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't believe Cortex XDR is capable of scanning file attachment, without saving the file first, or opening it. I would say your requirement is little hard to achieve. Someone may correct me but my understanding is a follow:&lt;/P&gt;
&lt;P&gt;- File is attached to email by encoding the file and adding it to the email body, which is simple text&lt;/P&gt;
&lt;P&gt;- When Outlook sync with exchange and receive the email (with the attachment), this email is stored in the .ost file (Offline Outlook data file)&lt;/P&gt;
&lt;P&gt;- Until this point the email attachment is not a file - from endpoint stand point of view.&lt;/P&gt;
&lt;P&gt;- If user tried to open the attachment, Outlook will first decode the attachment and save it in temporal location and run it from there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't have lot of experience with endpoint protections, but is hard for me to imagine that there is EDR/XDR which will allow you to scan attachment without saving it separately first.&lt;/P&gt;
&lt;P&gt;Email security protection is more suitable for such task. Such product will inspect the email, before being received by the exchange.&lt;/P&gt;
&lt;P&gt;You may have some success with firewall between endpoint and exchange, if you decrypt the traffic and email contain known virus/malware.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to use Cortex XDR your only option (in my humble opinion) is:&lt;BR /&gt;- User receive the email&lt;/P&gt;
&lt;P&gt;- User saves attachment as file&lt;/P&gt;
&lt;P&gt;- User right click on a file and select "scan with cortex xdr" (I am not sure what exact wording was)&lt;/P&gt;
&lt;P&gt;For this to work, your Malware profile -&amp;gt;&amp;nbsp; Endpoint Scan -&amp;gt; "End-user initiated local scan"&amp;nbsp; must be enabled (which is by default)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding your second question regarding blocking USB drives. This is achievable by using Extensions profiles - &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Device-Control" target="_blank"&gt;Device Control • Cortex XDR Prevent Administrator Guide • Reader • Palo Alto Networks documentation portal&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;With extension profiles, you can block any USB and add some exceptions or, allow any USB and add exceptions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note this way you will block any use of USB drives being plugin to the endpoint.&lt;/P&gt;
&lt;P&gt;Another way would be to use Restriction profile - &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-a-New-Restrictions-Security-Profile" target="_blank"&gt;Add a New Restrictions Security Profile • Cortex XDR Pro Administrator Guide • Reader • Palo Alto Networks documentation portal&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Using Restriction profiles, you can allow USB drive to be plugin, but block/prevent any execution from the attached plugin.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 15:42:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr/m-p/523712#M3242</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-12-09T15:42:37Z</dc:date>
    </item>
  </channel>
</rss>

