<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block versus Quarantine Malware Module Settings in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-versus-quarantine-malware-module-settings/m-p/562915#M5404</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/171707"&gt;@Joe_Botelho&lt;/a&gt;&amp;nbsp;Based on my understanding, block will only terminate the suspicious/malicious process a.k.a. causality chain. The files, configuration, code/script will remain in the affected system. In this case, the alert may re-occur until someone take remediation action against the system.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;If you enable the option to quarantine the file - depending on the module and alert - it will remove the file and stored it in a sub-directory of Cortex XDR. Due to the file is no longer available, it will not be able to execute and hence alert will not appear again. However, analyst need to review the quarantined file and make sure it is not a false-positive. Otherwise, a file restoration is required.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Oct 2023 09:54:48 GMT</pubDate>
    <dc:creator>Antony_Chan</dc:creator>
    <dc:date>2023-10-24T09:54:48Z</dc:date>
    <item>
      <title>Block versus Quarantine Malware Module Settings</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-versus-quarantine-malware-module-settings/m-p/562583#M5392</link>
      <description>&lt;P&gt;Is there a greater benefit to enabling the Quarantine setting versus the Block setting across the different modules in the Cortex XDR Malware profile? It is my understanding that both/either will result in the expected protective action (i.e. a potential threat will not be allowed to execute).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 14:04:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-versus-quarantine-malware-module-settings/m-p/562583#M5392</guid>
      <dc:creator>Joe_Botelho</dc:creator>
      <dc:date>2023-10-20T14:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: Block versus Quarantine Malware Module Settings</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-versus-quarantine-malware-module-settings/m-p/562674#M5395</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/171707"&gt;@Joe_Botelho&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out to Live Community. Please note that if the setting is configured to Quarantine then the file detected will be not allowed to execute and will be kept in a designated path for further analysis.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, when it comes to block mode, if a file is detected as malicious then it will be detected and destroyed and removed from the endpoint.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you. &lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 02:06:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-versus-quarantine-malware-module-settings/m-p/562674#M5395</guid>
      <dc:creator>abdrahman</dc:creator>
      <dc:date>2023-10-23T02:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: Block versus Quarantine Malware Module Settings</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-versus-quarantine-malware-module-settings/m-p/562915#M5404</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/171707"&gt;@Joe_Botelho&lt;/a&gt;&amp;nbsp;Based on my understanding, block will only terminate the suspicious/malicious process a.k.a. causality chain. The files, configuration, code/script will remain in the affected system. In this case, the alert may re-occur until someone take remediation action against the system.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;If you enable the option to quarantine the file - depending on the module and alert - it will remove the file and stored it in a sub-directory of Cortex XDR. Due to the file is no longer available, it will not be able to execute and hence alert will not appear again. However, analyst need to review the quarantined file and make sure it is not a false-positive. Otherwise, a file restoration is required.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 09:54:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-versus-quarantine-malware-module-settings/m-p/562915#M5404</guid>
      <dc:creator>Antony_Chan</dc:creator>
      <dc:date>2023-10-24T09:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: Block versus Quarantine Malware Module Settings</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-versus-quarantine-malware-module-settings/m-p/573980#M5926</link>
      <description>&lt;P&gt;Thank you for the responses. I think I am still not clear on whether it makes a difference to use block or quarantine in terms of protection. Block is designed prevent the execution of potentially malicious files/processes but so is quarantine. Right now, it seems that quarantine has the added step of moving the file into a sub-directory of XDR. But if you were to use the block setting, you are still protecting the endpoints. Please let me know if I am incorrect here.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 20:26:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-versus-quarantine-malware-module-settings/m-p/573980#M5926</guid>
      <dc:creator>Joe_Botelho</dc:creator>
      <dc:date>2024-01-22T20:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: Block versus Quarantine Malware Module Settings</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-versus-quarantine-malware-module-settings/m-p/580286#M6322</link>
      <description>&lt;P&gt;&lt;SPAN&gt;To clarify, the "Block and Quarantine Disabled" setting is designed to prevent the execution of the executable files but does not necessarily remove the files permanently. It effectively blocks the file from running but leaves the file intact.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 21:07:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-versus-quarantine-malware-module-settings/m-p/580286#M6322</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-03-13T21:07:38Z</dc:date>
    </item>
    <item>
      <title>Re: Block versus Quarantine Malware Module Settings</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-versus-quarantine-malware-module-settings/m-p/580385#M6333</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt;&amp;nbsp;for the clarification.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 12:11:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-versus-quarantine-malware-module-settings/m-p/580385#M6333</guid>
      <dc:creator>MosR</dc:creator>
      <dc:date>2024-03-14T12:11:55Z</dc:date>
    </item>
  </channel>
</rss>

