<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex Domain controllers exceptions in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-domain-controllers-exceptions/m-p/535473#M3915</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi &lt;/SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/145475" target="_blank"&gt;&lt;SPAN&gt;@Majid1Khan&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I’ve taken a look at your list of exceptions received from Microsoft.&amp;nbsp; It appears that some of them are individual files/file types.&amp;nbsp; Others such as $db_normal$ appear to refer to a certain location on disk.&amp;nbsp; Looking at this &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-server-exclusions-microsoft-defender-antivirus?view=o365-worldwide" target="_blank"&gt;&lt;SPAN&gt;Microsoft documentation&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; I was able to find references to what you were given.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;SYSVOL Exceptions&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;$db_normal$ - &lt;/SPAN&gt;&lt;STRONG&gt;See below&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;FileIDTable_* - &lt;/SPAN&gt;&lt;STRONG&gt;See below&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;SimilarityTable_* - &lt;/SPAN&gt;&lt;STRONG&gt;See below&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;*.xml - &lt;/SPAN&gt;&lt;STRONG&gt;File Type&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;$db_dirty$ - &lt;/SPAN&gt;&lt;STRONG&gt;See below&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;$db_clean$ - &lt;/SPAN&gt;&lt;STRONG&gt;See below&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;$db_lost$ -&lt;/SPAN&gt;&lt;STRONG&gt; See below&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Dfsr.db - &lt;/SPAN&gt;&lt;STRONG&gt;File Type&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Fsr.chk - &lt;/SPAN&gt;&lt;STRONG&gt;File Type&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;*.frx - &lt;/SPAN&gt;&lt;STRONG&gt;File Type&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;*.log - &lt;/SPAN&gt;&lt;STRONG&gt;File Type&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Fsr*.jrs - &lt;/SPAN&gt;&lt;STRONG&gt;File Type&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Tmp.edb - &lt;/SPAN&gt;&lt;STRONG&gt;File Type&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anlynch_0-1679504249225.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48959i56FBC0554C9DD251/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anlynch_0-1679504249225.png" alt="anlynch_0-1679504249225.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anlynch_1-1679504249307.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48960iFE858FADEF0C7C02/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anlynch_1-1679504249307.png" alt="anlynch_1-1679504249307.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In the screenshot above you can see a lot of the file types you mentioned in your previous post.&amp;nbsp; I hope this helps clarify the exceptions you would need to input into Cortex XDR.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please reply to this comment if you have any further questions.&amp;nbsp; We’re happy to help.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Have a great day!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Mar 2023 16:57:50 GMT</pubDate>
    <dc:creator>anlynch</dc:creator>
    <dc:date>2023-03-22T16:57:50Z</dc:date>
    <item>
      <title>Cortex Domain controllers exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-domain-controllers-exceptions/m-p/535394#M3910</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are having replication issues across the domain controllers and Microsoft is suspecting its an issue with Cortex and they want the the below files to be created as an exceptions across all our domain controllers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To rule out Cortex issue we thought we will put this DC's in report mode instead of Block, as it is a risk of keeping DC's in report mode for longer duration till the replication is completed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But im not able to add the below in the exclusions as it is not allowing this format in Cortex, please advise?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;The following will need to be exception in Cortex AV. Once exceptioned and the list of files waiting to be replicated drops then Microsoft will investigate further.&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&lt;STRONG&gt;&lt;U&gt;SYSVOL Exceptions&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;$db_normal$&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;FileIDTable_*&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;SimilarityTable_*&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;*.xml&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;$db_dirty$&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;$db_clean$&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;$db_lost$&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;Dfsr.db&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;Fsr.chk&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;*.frx&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;*.log&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;Fsr*.jrs&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;Tmp.edb&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 12:00:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-domain-controllers-exceptions/m-p/535394#M3910</guid>
      <dc:creator>Majid1Khan</dc:creator>
      <dc:date>2023-03-22T12:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex Domain controllers exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-domain-controllers-exceptions/m-p/535433#M3913</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/145475"&gt;@Majid1Khan&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm researching this issue for you now and will get back to you as quickly as I can.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 14:47:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-domain-controllers-exceptions/m-p/535433#M3913</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-03-22T14:47:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex Domain controllers exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-domain-controllers-exceptions/m-p/535473#M3915</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi &lt;/SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/145475" target="_blank"&gt;&lt;SPAN&gt;@Majid1Khan&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I’ve taken a look at your list of exceptions received from Microsoft.&amp;nbsp; It appears that some of them are individual files/file types.&amp;nbsp; Others such as $db_normal$ appear to refer to a certain location on disk.&amp;nbsp; Looking at this &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-server-exclusions-microsoft-defender-antivirus?view=o365-worldwide" target="_blank"&gt;&lt;SPAN&gt;Microsoft documentation&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; I was able to find references to what you were given.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;SYSVOL Exceptions&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;$db_normal$ - &lt;/SPAN&gt;&lt;STRONG&gt;See below&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;FileIDTable_* - &lt;/SPAN&gt;&lt;STRONG&gt;See below&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;SimilarityTable_* - &lt;/SPAN&gt;&lt;STRONG&gt;See below&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;*.xml - &lt;/SPAN&gt;&lt;STRONG&gt;File Type&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;$db_dirty$ - &lt;/SPAN&gt;&lt;STRONG&gt;See below&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;$db_clean$ - &lt;/SPAN&gt;&lt;STRONG&gt;See below&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;$db_lost$ -&lt;/SPAN&gt;&lt;STRONG&gt; See below&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Dfsr.db - &lt;/SPAN&gt;&lt;STRONG&gt;File Type&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Fsr.chk - &lt;/SPAN&gt;&lt;STRONG&gt;File Type&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;*.frx - &lt;/SPAN&gt;&lt;STRONG&gt;File Type&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;*.log - &lt;/SPAN&gt;&lt;STRONG&gt;File Type&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Fsr*.jrs - &lt;/SPAN&gt;&lt;STRONG&gt;File Type&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Tmp.edb - &lt;/SPAN&gt;&lt;STRONG&gt;File Type&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anlynch_0-1679504249225.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48959i56FBC0554C9DD251/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anlynch_0-1679504249225.png" alt="anlynch_0-1679504249225.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anlynch_1-1679504249307.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48960iFE858FADEF0C7C02/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anlynch_1-1679504249307.png" alt="anlynch_1-1679504249307.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In the screenshot above you can see a lot of the file types you mentioned in your previous post.&amp;nbsp; I hope this helps clarify the exceptions you would need to input into Cortex XDR.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please reply to this comment if you have any further questions.&amp;nbsp; We’re happy to help.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Have a great day!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 16:57:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-domain-controllers-exceptions/m-p/535473#M3915</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-03-22T16:57:50Z</dc:date>
    </item>
  </channel>
</rss>

