<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: path exclusion for scans do not work in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/path-exclusion-for-scans-do-not-work/m-p/527534#M3412</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/159101"&gt;@S-LEGOUGE&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for writting us in livecommunity.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Im sorry that your message got unanswered for a while, Ive just found it unanswered.&lt;/P&gt;
&lt;P&gt;After reading your message and realizing about your issue, I would recommend to open a TAC support ticket.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helped,&lt;/P&gt;
&lt;P&gt;eLuis&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Jan 2023 10:01:04 GMT</pubDate>
    <dc:creator>eluis</dc:creator>
    <dc:date>2023-01-18T10:01:04Z</dc:date>
    <item>
      <title>path exclusion for scans do not work</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/path-exclusion-for-scans-do-not-work/m-p/523494#M3231</link>
      <description>&lt;P&gt;Hello to all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am experiencing a problem on a machine where scans are pushing the overall CPU load to 100% for several minutes to several hours and only slowly decreasing.&lt;/P&gt;
&lt;P&gt;This causes problems for the use of the Syngo.Via software installed on this machine and the syngo.via server is not responding, the syngo.via clients are not usable and freeze/plant or respond very slowly.&lt;/P&gt;
&lt;P&gt;In the documentation of this software there are exclusions to be made in the antivirus:&lt;BR /&gt;- C:\ISPACE\*.* (if present)&lt;BR /&gt;-&amp;nbsp;C:\Program Files\Siemens\*.*&lt;BR /&gt;- C:\Program Files (x86)\Siemens\*.*&lt;BR /&gt;- C:\store\*.*&lt;BR /&gt;- C:\sysmgtmt\*&lt;BR /&gt;- C:\WindowsInstaller*.&lt;BR /&gt;- D:\SQL_DATA\*.*&lt;BR /&gt;- D:\MSSQL13.MSSQLSERVER_SYDS\*.* ([13] depends on the instance)&lt;BR /&gt;- E:\frontier\* (if present)&lt;BR /&gt;- E:\storagefw\*.&lt;BR /&gt;- E:\sysmgtmt\*.&lt;BR /&gt;- M:\BackupRestore\MSSQL&lt;BR /&gt;- N:\WindowsImageBackup\*.&lt;BR /&gt;-S:\*.*&lt;/P&gt;
&lt;P&gt;as well as the options to be deactivated:&lt;/P&gt;
&lt;P&gt;-&lt;BR /&gt;Do not scan compressed files.&lt;BR /&gt;No compressed files should be scanned as this may lead to performance issues. However, scan compressed files during scheduled full scans!&lt;BR /&gt;-&lt;BR /&gt;Deactivate heuristic search.&lt;BR /&gt;Heuristic search should not be activated as the risk of false positives may arise.&lt;BR /&gt;-&lt;BR /&gt;Deactivate advanced intrusion detection/prevention (IDS/IPS) and firewall features.&lt;BR /&gt;Virus protection suites (for example, suites including firewall and intrusion detection applications) are not supported. Deactivate additional features.&lt;BR /&gt;- If you are able to define a default warning text in case an infected file is found, set it to "Virus Scan Alert!&lt;BR /&gt;- Only the following actions should be performed if an infected file is found:&lt;BR /&gt;- Set the found file to quarantine.&lt;BR /&gt;- Write an event to the event log.&lt;BR /&gt;To prevent data loss in case of false positives, do not delete or repair infected files automatically. You have to check files manually and delete them if necessary.&lt;BR /&gt;- Only the following actions should be performed if spyware, adware, dialers, hack tools, trackware, password crackers, trojans, joke p programs, or key loggers are found:&lt;BR /&gt;- Set the found file to quarantine.&lt;BR /&gt;- Write an event to the event log.&lt;BR /&gt;- In case of remote administrator tools, ignore findings but create events.&lt;BR /&gt;- In case of other unwanted programs, ignore findings but create events.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;All paths have been added to all modules of the malware profile&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did add these paths to the exclusions but cortex keeps scanning them, I don't know why can you help me?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And where to disable Syngo recommendations (compressed, heuristic, etc )?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2022 14:27:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/path-exclusion-for-scans-do-not-work/m-p/523494#M3231</guid>
      <dc:creator>S-LEGOUGE</dc:creator>
      <dc:date>2022-12-07T14:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: path exclusion for scans do not work</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/path-exclusion-for-scans-do-not-work/m-p/527534#M3412</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/159101"&gt;@S-LEGOUGE&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for writting us in livecommunity.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Im sorry that your message got unanswered for a while, Ive just found it unanswered.&lt;/P&gt;
&lt;P&gt;After reading your message and realizing about your issue, I would recommend to open a TAC support ticket.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helped,&lt;/P&gt;
&lt;P&gt;eLuis&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 10:01:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/path-exclusion-for-scans-do-not-work/m-p/527534#M3412</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2023-01-18T10:01:04Z</dc:date>
    </item>
    <item>
      <title>Re: path exclusion for scans do not work</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/path-exclusion-for-scans-do-not-work/m-p/527535#M3413</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190764"&gt;@eluis&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One case is currently open and troubleshooting is underway with support.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 10:09:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/path-exclusion-for-scans-do-not-work/m-p/527535#M3413</guid>
      <dc:creator>S-LEGOUGE</dc:creator>
      <dc:date>2023-01-18T10:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: path exclusion for scans do not work</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/path-exclusion-for-scans-do-not-work/m-p/572856#M5872</link>
      <description>&lt;P&gt;Was this ever solved? If yes, how? Maybe with a support exception that is disabling syscalls?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 11:07:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/path-exclusion-for-scans-do-not-work/m-p/572856#M5872</guid>
      <dc:creator>OMI_RLI</dc:creator>
      <dc:date>2024-01-12T11:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: path exclusion for scans do not work</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/path-exclusion-for-scans-do-not-work/m-p/616401#M7411</link>
      <description>&lt;P&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;we have the same problem.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;Excluding all this number of directories, as requested in Siemens documentation, opens the door to injecting malicious stuff.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="jCAhz"&gt;&lt;SPAN class="ryNqvb"&gt; Thanks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 07:12:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/path-exclusion-for-scans-do-not-work/m-p/616401#M7411</guid>
      <dc:creator>adeprt1705</dc:creator>
      <dc:date>2024-11-08T07:12:29Z</dc:date>
    </item>
  </channel>
</rss>

