<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR Blockage activity in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blockage-activity/m-p/532744#M3738</link>
    <description>&lt;P&gt;If anything needed executable are blocked by the XDR previous we used to add that ***.exe in malware profile. But now we faced that issue that client has connected the clickshare(PC Screen Share) Equipment as it's an external equipment connected to USB of the machine. How can we add that .exe to exception list to work in the machine. Its not working If add that in the malware profile.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Mar 2023 20:07:10 GMT</pubDate>
    <dc:creator>VineethArumulla</dc:creator>
    <dc:date>2023-03-01T20:07:10Z</dc:date>
    <item>
      <title>Cortex XDR Blockage activity</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blockage-activity/m-p/532744#M3738</link>
      <description>&lt;P&gt;If anything needed executable are blocked by the XDR previous we used to add that ***.exe in malware profile. But now we faced that issue that client has connected the clickshare(PC Screen Share) Equipment as it's an external equipment connected to USB of the machine. How can we add that .exe to exception list to work in the machine. Its not working If add that in the malware profile.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 20:07:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blockage-activity/m-p/532744#M3738</guid>
      <dc:creator>VineethArumulla</dc:creator>
      <dc:date>2023-03-01T20:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Blockage activity</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blockage-activity/m-p/532771#M3740</link>
      <description>&lt;P&gt;Hi VineethArumulla,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Are you saying you are unable to add the file in the malware profile like you previously were able to? Or you were able to add the file but the traffic is still being blocked?&lt;BR /&gt;&lt;BR /&gt;In the last XDR version release (3.5), the workflow for managing exceptions and module allow-listing changed a bit. Navigate to Settings&amp;gt;Exceptions Configuration&amp;gt;Legacy Agent Exceptions then in the top right of the page click "Add&amp;nbsp;Rule". As you navigate through the rule creation wizard you will need to define a name for the rule, select the associated platform, select which endpoint protection module you are wanting the exception applied to, define the target properties, then select which profile(s) you want the exception applied to. Once the rule is saved it will be applied to the associated endpoints at their next check-in.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Ben&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 22:24:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blockage-activity/m-p/532771#M3740</guid>
      <dc:creator>bbucao</dc:creator>
      <dc:date>2023-03-01T22:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Blockage activity</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blockage-activity/m-p/532927#M3749</link>
      <description>&lt;P&gt;We're able to add the file in malware profile but the traffic is still blocking, So we added the same file in restriction profile, Is that correct path? Is there any changes in the XDR 7.8.0 version?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 12:12:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blockage-activity/m-p/532927#M3749</guid>
      <dc:creator>VineethArumulla</dc:creator>
      <dc:date>2023-03-02T12:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Blockage activity</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blockage-activity/m-p/533044#M3755</link>
      <description>&lt;P&gt;Hi VineethArumulla,&lt;BR /&gt;&lt;BR /&gt;I do not recommend using the restrictions profile in this way as it could cause unexpected&amp;nbsp; behavior since that is not the intended function.&lt;BR /&gt;The allow-lists you are referring to in the malware profile are module specific, so it is important to make sure you are applying the setting to the correct module. In the alerts table, look in the "module" field for this alert, then make sure you are adding the file/path to the corresponding module allow-list in the malware profile. Keep in mind that in some cases a file may trigger multiple modules, in which case you would need to add the file to all applicable module allow-lists. If you have already done this and the traffic continues to be blocked, I would recommend opening a support case to address the issue.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Ben&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 22:41:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blockage-activity/m-p/533044#M3755</guid>
      <dc:creator>bbucao</dc:creator>
      <dc:date>2023-03-02T22:41:27Z</dc:date>
    </item>
  </channel>
</rss>

