<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to block  Excel macros in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-block-excel-macros/m-p/536802#M3976</link>
    <description>&lt;P&gt;Try to block threat events 39154.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_0-1680016039109.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49067i10594A8CB32CF2BD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_0-1680016039109.png" alt="Raido_Rattameister_0-1680016039109.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_1-1680016120230.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49068iAA77AB503FF306EE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_1-1680016120230.png" alt="Raido_Rattameister_1-1680016120230.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Mar 2023 15:19:45 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2023-03-28T15:19:45Z</dc:date>
    <item>
      <title>How to block  Excel macros</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-block-excel-macros/m-p/536778#M3974</link>
      <description>&lt;P&gt;we have a new requirement we need to block&amp;nbsp;&amp;nbsp;&amp;nbsp;Excel macros for specific groups of user&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;anyone know how to block&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 10:25:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-block-excel-macros/m-p/536778#M3974</guid>
      <dc:creator>RajeshPremSingh</dc:creator>
      <dc:date>2023-03-28T10:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to block  Excel macros</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-block-excel-macros/m-p/536802#M3976</link>
      <description>&lt;P&gt;Try to block threat events 39154.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_0-1680016039109.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49067i10594A8CB32CF2BD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_0-1680016039109.png" alt="Raido_Rattameister_0-1680016039109.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_1-1680016120230.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49068iAA77AB503FF306EE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_1-1680016120230.png" alt="Raido_Rattameister_1-1680016120230.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 15:19:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-block-excel-macros/m-p/536802#M3976</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-03-28T15:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to block  Excel macros</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-block-excel-macros/m-p/536804#M3977</link>
      <description>&lt;P&gt;Could you please tell me how to integrate the rule with Cortex XDR?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 15:25:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-block-excel-macros/m-p/536804#M3977</guid>
      <dc:creator>RajeshPremSingh</dc:creator>
      <dc:date>2023-03-28T15:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to block  Excel macros</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-block-excel-macros/m-p/536809#M3980</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/262549"&gt;@RajeshPremSingh&lt;/a&gt;&amp;nbsp;, thank you for writing to Live Community.&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;You can create a new &lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-a-New-Malware-Security-Profile" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;malware security profile &lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;by going into Endpoints → policy management → add profile → choose OS → Malware →Office Files with Macros Examination (see screenshot attached). There, you can choose which action will be taken based on the policy you create.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mavraham_0-1680020337451.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49072iE0BDCDB9F1E3EFFF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mavraham_0-1680020337451.png" alt="mavraham_0-1680020337451.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;After creating the profile, the next step would be to &lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Endpoint-Data-Collection" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;apply the new security profiles to endpoint&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;(s). &lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Go into Policy Management → Add Policy → Create New → Enter policy name and select platform → Select the malware profile you created (see screenshot for example) → click next to choose which endpoints it will apply to and confirm the action.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mavraham_1-1680020378021.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49073i5851A51F0D3CF196/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mavraham_1-1680020378021.png" alt="mavraham_1-1680020378021.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;I’ve attached links to our documentation about how to create new security profiles and apply them to endpoints in case you are looking for more information.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Hope this helps!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 16:35:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-block-excel-macros/m-p/536809#M3980</guid>
      <dc:creator>mavraham</dc:creator>
      <dc:date>2023-03-28T16:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to block  Excel macros</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-block-excel-macros/m-p/536876#M3983</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167148"&gt;@mavraham&lt;/a&gt;&amp;nbsp; Thanks for your Response,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's great help for us. We followed your mentioned steps. but it&amp;nbsp;only blocks any malicious macros embedded in the office.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Excel Macros.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49089i2BF83570EF70BE70/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Excel Macros.png" alt="Excel Macros.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we need to block the start and stop macro options.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Macro Start.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49090i452BA313D5DDAC7F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Macro Start.png" alt="Macro Start.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If is this macro option block is possible? please let us know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 07:30:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-block-excel-macros/m-p/536876#M3983</guid>
      <dc:creator>Thendral_Arasu</dc:creator>
      <dc:date>2023-03-29T07:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to block  Excel macros</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-block-excel-macros/m-p/537107#M3994</link>
      <description>&lt;P&gt;Hi ThendralMandu,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We do not support blocking this capability.&amp;nbsp; Cortex XDR is designed to prevent malicious applications and behaviors from running on your endpoints, it is not designed to be an endpoint control application.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 14:00:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-block-excel-macros/m-p/537107#M3994</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2023-03-30T14:00:06Z</dc:date>
    </item>
  </channel>
</rss>

