<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Export allow list in prevention profile &amp;quot;Malware&amp;quot; in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/export-allow-list-in-prevention-profile-quot-malware-quot/m-p/551022#M4828</link>
    <description>&lt;P&gt;Hello &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any solution to export the &lt;SPAN class="header-context-info"&gt;&lt;SPAN class="grid-header-left-side ng-star-inserted"&gt;&lt;SPAN class="grid-header-name-text ng-star-inserted" title="Prevention Profiles"&gt;allow list in prevention profiles? &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="header-context-info"&gt;&lt;SPAN class="grid-header-left-side ng-star-inserted"&gt;&lt;SPAN class="grid-header-name-text ng-star-inserted" title="Prevention Profiles"&gt;For an example the malware profile?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="header-context-info"&gt;&lt;SPAN class="grid-header-left-side ng-star-inserted"&gt;&lt;SPAN class="grid-header-name-text ng-star-inserted" title="Prevention Profiles"&gt;I already checked in XQL. &lt;BR /&gt;Found no dataset where these informations could be exist.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone any suggestions?&lt;BR /&gt;&lt;BR /&gt;Cheers &lt;BR /&gt;Tobias&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jul 2023 07:34:56 GMT</pubDate>
    <dc:creator>Tobias_Bartsch</dc:creator>
    <dc:date>2023-07-26T07:34:56Z</dc:date>
    <item>
      <title>Export allow list in prevention profile "Malware"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/export-allow-list-in-prevention-profile-quot-malware-quot/m-p/551022#M4828</link>
      <description>&lt;P&gt;Hello &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any solution to export the &lt;SPAN class="header-context-info"&gt;&lt;SPAN class="grid-header-left-side ng-star-inserted"&gt;&lt;SPAN class="grid-header-name-text ng-star-inserted" title="Prevention Profiles"&gt;allow list in prevention profiles? &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="header-context-info"&gt;&lt;SPAN class="grid-header-left-side ng-star-inserted"&gt;&lt;SPAN class="grid-header-name-text ng-star-inserted" title="Prevention Profiles"&gt;For an example the malware profile?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="header-context-info"&gt;&lt;SPAN class="grid-header-left-side ng-star-inserted"&gt;&lt;SPAN class="grid-header-name-text ng-star-inserted" title="Prevention Profiles"&gt;I already checked in XQL. &lt;BR /&gt;Found no dataset where these informations could be exist.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone any suggestions?&lt;BR /&gt;&lt;BR /&gt;Cheers &lt;BR /&gt;Tobias&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 07:34:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/export-allow-list-in-prevention-profile-quot-malware-quot/m-p/551022#M4828</guid>
      <dc:creator>Tobias_Bartsch</dc:creator>
      <dc:date>2023-07-26T07:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: Export allow list in prevention profile "Malware"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/export-allow-list-in-prevention-profile-quot-malware-quot/m-p/551274#M4834</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/217204"&gt;@Tobias_Bartsch&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Unfortunately, there is no option to export allow-list within malware profile in Cortex XDR at this point. However if idea is to use this allow list&amp;nbsp;in new malware profile in the same Cortex XDR tenant/management console then you may try this workaround.&lt;BR /&gt;&lt;BR /&gt;1. Export the Malware profile whose allow-list you would want to be used in new Malware profile.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. Rename the above malware profile which has been exported to avoid same profile name conflict.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3. Import the Malware profile which was exported at Step 1 and you will have same allow list&amp;nbsp;in this profile. Now you may edit/update the profile name as desired.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank You&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 07:09:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/export-allow-list-in-prevention-profile-quot-malware-quot/m-p/551274#M4834</guid>
      <dc:creator>PiyushKohli</dc:creator>
      <dc:date>2023-07-27T07:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: Export allow list in prevention profile "Malware"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/export-allow-list-in-prevention-profile-quot-malware-quot/m-p/551275#M4835</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/276269"&gt;@PiyushKohli&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;first of all: thanks for you reply &lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt; &lt;span class="lia-unicode-emoji" title=":handshake:"&gt;🤝&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I already knew the export / import feature. That´s not new to me.&lt;/P&gt;
&lt;P&gt;But unfortunately this is not the solution to my problem.&lt;BR /&gt;&lt;BR /&gt;We would like to control / check the exceptions at regular intervals and document them in our internal documentation.&lt;BR /&gt;The exceptions must be stored somewhere in the tenant, so that a retrieval via XQL or API should be possible. &lt;BR /&gt;The export of the profiles does not help at all, because this is &lt;BR /&gt;1. is encrypted and &lt;BR /&gt;2. does not contain the exceptions.&lt;BR /&gt;&lt;BR /&gt;Are there any other ideas?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 07:11:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/export-allow-list-in-prevention-profile-quot-malware-quot/m-p/551275#M4835</guid>
      <dc:creator>Tobias_Bartsch</dc:creator>
      <dc:date>2023-07-27T07:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: Export allow list in prevention profile "Malware"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/export-allow-list-in-prevention-profile-quot-malware-quot/m-p/551284#M4837</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/217204"&gt;@Tobias_Bartsch&lt;/a&gt;&amp;nbsp;for sharing additional details i.e. "&lt;SPAN&gt;We would like to control / check the exceptions at regular intervals and document them in our internal documentation."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Since your use case here is to capture allow list&amp;nbsp;for internal documentation then you may try the following workaround - i.e. to capture response in browser developer tools by editing the profile. Now from the response you may extract the allowlist value as shared in below screenshot.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PiyushKohli_1-1690444413350.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52248i8A049305000BD0DB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PiyushKohli_1-1690444413350.png" alt="PiyushKohli_1-1690444413350.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 07:57:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/export-allow-list-in-prevention-profile-quot-malware-quot/m-p/551284#M4837</guid>
      <dc:creator>PiyushKohli</dc:creator>
      <dc:date>2023-07-27T07:57:08Z</dc:date>
    </item>
    <item>
      <title>Re: Export allow list in prevention profile "Malware"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/export-allow-list-in-prevention-profile-quot-malware-quot/m-p/551285#M4838</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/276269"&gt;@PiyushKohli&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;many thanks for this advice &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Works perfectly &lt;span class="lia-unicode-emoji" title=":raising_hands:"&gt;🙌&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks and kind regards &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;
&lt;P&gt;Tobias&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 08:04:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/export-allow-list-in-prevention-profile-quot-malware-quot/m-p/551285#M4838</guid>
      <dc:creator>Tobias_Bartsch</dc:creator>
      <dc:date>2023-07-27T08:04:08Z</dc:date>
    </item>
  </channel>
</rss>

