<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Whitelisting of Files in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/whitelisting-of-files/m-p/523981#M3253</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Yes, you can whitelist the file hash by going into Incident Response → Action Center → New Action – Add to allow list.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Please note that once the file changes (via updates for example) you will need to whitelist the new hash again.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;If you know the signature of your verified software, you can also add the singer as a trusted signer when creating a new malware profile (the page I recommended in the above response).&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 13 Dec 2022 16:51:14 GMT</pubDate>
    <dc:creator>mavraham</dc:creator>
    <dc:date>2022-12-13T16:51:14Z</dc:date>
    <item>
      <title>Whitelisting of Files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/whitelisting-of-files/m-p/523846#M3246</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are running periodic scan on all endpoints . During this scan few files has been detected .We have&amp;nbsp; got confirmation that some of the files are legitimate and it's being used in infra.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please suggest in providing what is the best method to whitelist the safe and confirmed files .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2022 19:47:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/whitelisting-of-files/m-p/523846#M3246</guid>
      <dc:creator>Shashanksinha</dc:creator>
      <dc:date>2022-12-12T19:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: Whitelisting of Files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/whitelisting-of-files/m-p/523858#M3248</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203123"&gt;@Shashanksinha&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Thank you for writing to Live Community.&lt;BR /&gt;&lt;BR /&gt;You would need to&amp;nbsp;&lt;SPAN&gt;can create a malware profile and exclude specific files from scans.&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004Nw2CAE&amp;amp;lang=en_US%E2%80%A9" target="_self"&gt;This page&lt;/A&gt;&amp;nbsp;should guide you how to proceed.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2022 21:59:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/whitelisting-of-files/m-p/523858#M3248</guid>
      <dc:creator>mavraham</dc:creator>
      <dc:date>2022-12-12T21:59:15Z</dc:date>
    </item>
    <item>
      <title>Re: Whitelisting of Files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/whitelisting-of-files/m-p/523908#M3251</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your response.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As you mentioned to create malware profile and exclude specific files from scans, as&amp;nbsp;we have multiple files present in different folders so it will be difficult to add every path with *. If we whitelist the file hash does this exclude from scans?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 11:46:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/whitelisting-of-files/m-p/523908#M3251</guid>
      <dc:creator>RamyashreeMada</dc:creator>
      <dc:date>2022-12-13T11:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Whitelisting of Files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/whitelisting-of-files/m-p/523981#M3253</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Yes, you can whitelist the file hash by going into Incident Response → Action Center → New Action – Add to allow list.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Please note that once the file changes (via updates for example) you will need to whitelist the new hash again.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;If you know the signature of your verified software, you can also add the singer as a trusted signer when creating a new malware profile (the page I recommended in the above response).&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 16:51:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/whitelisting-of-files/m-p/523981#M3253</guid>
      <dc:creator>mavraham</dc:creator>
      <dc:date>2022-12-13T16:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: Whitelisting of Files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/whitelisting-of-files/m-p/524058#M3259</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Thanks for responding.&lt;/P&gt;
&lt;P&gt;If we add the hash of the file in allow list .So does alerts/incidents excludes in the malware scan. .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As we are observing incidents/alerts for the files despite being in allow list.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 09:03:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/whitelisting-of-files/m-p/524058#M3259</guid>
      <dc:creator>Shashanksinha</dc:creator>
      <dc:date>2022-12-14T09:03:13Z</dc:date>
    </item>
    <item>
      <title>Re: Whitelisting of Files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/whitelisting-of-files/m-p/524085#M3260</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203123"&gt;@Shashanksinha&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Please note that adding file hash to the allowlist will &lt;SPAN&gt;bypass the verdict of WF or local analysis, it will not prevent alerts generated by BTP rules, and alerts can still be triggered by child processes&amp;nbsp;.&lt;BR /&gt;&lt;BR /&gt;In case your alerts are triggered&amp;nbsp;by BTP rules, you can&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Add-a-Global-Endpoint-Policy-Exception" target="_self"&gt;add a Global Behavioral Threat Protection (BTP) Rule Exception.&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 12:10:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/whitelisting-of-files/m-p/524085#M3260</guid>
      <dc:creator>mavraham</dc:creator>
      <dc:date>2022-12-14T12:10:37Z</dc:date>
    </item>
  </channel>
</rss>

