<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Response Action in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/response-action/m-p/547394#M4649</link>
    <description>&lt;P&gt;There is an option Response Action under agent configuration, which means we can allow access to a certain application in case the endpoint is isolated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which application access should ideally be provided in it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 27 Jun 2023 12:09:28 GMT</pubDate>
    <dc:creator>Shahwaz_Md</dc:creator>
    <dc:date>2023-06-27T12:09:28Z</dc:date>
    <item>
      <title>Response Action</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/response-action/m-p/547394#M4649</link>
      <description>&lt;P&gt;There is an option Response Action under agent configuration, which means we can allow access to a certain application in case the endpoint is isolated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which application access should ideally be provided in it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 12:09:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/response-action/m-p/547394#M4649</guid>
      <dc:creator>Shahwaz_Md</dc:creator>
      <dc:date>2023-06-27T12:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: Response Action</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/response-action/m-p/547424#M4653</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/236325"&gt;@Shahwaz_Md&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out to Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you isolate an endpoint, it will halt all network traffic except for cortex XDR traffic. "Response Actions" feature under Agent settings profile allow you to add specific applications to be allowed in case of Network Isolation.&lt;/P&gt;
&lt;P&gt;Allowing a specific application depends on the customer environment and use cases. There is no recommendation from our side.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example,&amp;nbsp;&lt;/P&gt;
&lt;UL class="itemizedlist"&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;(&lt;SPAN class="monospaced"&gt;Windows&lt;/SPAN&gt;) For VDI sessions, using the network isolation response action can disrupt communication with the VDI host management system thereby halting access to the VDI session. As a result, before using the response action you must add the VDI processes and corresponding IP addresses to your allow list.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="listitem"&gt;Some customer may want Windows Update service to continue to work even in isolation.&lt;/LI&gt;
&lt;LI class="listitem"&gt;Some may want to allow access to some other security tool e.g. DLP.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Please keep network access to bare minimum in case of Isolation to restrict&amp;nbsp;&lt;SPAN&gt;attacker’s mobility on your network. Below is the link for your reference.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Response-Actions" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Response-Actions&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 14:24:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/response-action/m-p/547424#M4653</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2023-06-27T14:24:30Z</dc:date>
    </item>
  </channel>
</rss>

