<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PortableApps - Block all in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/portableapps-block-all/m-p/569255#M5693</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hello, I would like to know if anyone has ever blocked portable applications...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; We would like to block PortableApps (PortableApps.com)... without blocking them one by one, as there are many. Has anyone ever blocked them using a wildcard in the process name? I know it's not entirely secure to block solely based on the process name, but it would be helpful...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="flex-1 overflow-hidden"&gt;
&lt;DIV class="react-scroll-to-bottom--css-tumpv-79elbk h-full"&gt;
&lt;DIV class="react-scroll-to-bottom--css-tumpv-1n7m0yu"&gt;
&lt;DIV class="flex flex-col pb-9 text-sm"&gt;
&lt;DIV class="w-full text-token-text-primary" data-testid="conversation-turn-16"&gt;
&lt;DIV class="px-4 py-2 justify-center text-base md:gap-6 m-auto"&gt;
&lt;DIV class="flex flex-1 text-base mx-auto gap-3 md:px-5 lg:px-1 xl:px-5 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem] } group final-completion"&gt;
&lt;DIV class="relative flex w-full flex-col lg:w-[calc(100%-115px)] agent-turn"&gt;
&lt;DIV class="flex-col gap-1 md:gap-3"&gt;
&lt;DIV class="flex flex-grow flex-col max-w-full"&gt;
&lt;DIV class="min-h-[20px] text-message flex flex-col items-start gap-3 whitespace-pre-wrap break-words [.text-message+&amp;amp;]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="cc814da3-997b-4586-b1f0-43aee9f88ab2"&gt;
&lt;DIV class="markdown prose w-full break-words dark:prose-invert dark"&gt;
&lt;P&gt;Does anyone have any ideas or suggestions?&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 11 Dec 2023 11:49:34 GMT</pubDate>
    <dc:creator>tlmarques</dc:creator>
    <dc:date>2023-12-11T11:49:34Z</dc:date>
    <item>
      <title>PortableApps - Block all</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/portableapps-block-all/m-p/569255#M5693</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello, I would like to know if anyone has ever blocked portable applications...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; We would like to block PortableApps (PortableApps.com)... without blocking them one by one, as there are many. Has anyone ever blocked them using a wildcard in the process name? I know it's not entirely secure to block solely based on the process name, but it would be helpful...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="flex-1 overflow-hidden"&gt;
&lt;DIV class="react-scroll-to-bottom--css-tumpv-79elbk h-full"&gt;
&lt;DIV class="react-scroll-to-bottom--css-tumpv-1n7m0yu"&gt;
&lt;DIV class="flex flex-col pb-9 text-sm"&gt;
&lt;DIV class="w-full text-token-text-primary" data-testid="conversation-turn-16"&gt;
&lt;DIV class="px-4 py-2 justify-center text-base md:gap-6 m-auto"&gt;
&lt;DIV class="flex flex-1 text-base mx-auto gap-3 md:px-5 lg:px-1 xl:px-5 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem] } group final-completion"&gt;
&lt;DIV class="relative flex w-full flex-col lg:w-[calc(100%-115px)] agent-turn"&gt;
&lt;DIV class="flex-col gap-1 md:gap-3"&gt;
&lt;DIV class="flex flex-grow flex-col max-w-full"&gt;
&lt;DIV class="min-h-[20px] text-message flex flex-col items-start gap-3 whitespace-pre-wrap break-words [.text-message+&amp;amp;]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="cc814da3-997b-4586-b1f0-43aee9f88ab2"&gt;
&lt;DIV class="markdown prose w-full break-words dark:prose-invert dark"&gt;
&lt;P&gt;Does anyone have any ideas or suggestions?&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Dec 2023 11:49:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/portableapps-block-all/m-p/569255#M5693</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2023-12-11T11:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: PortableApps - Block all</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/portableapps-block-all/m-p/569295#M5696</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did some reasearch, and all the executable files are signed by "Rare Ideas, LLC", it means that you can create a custom BIOC rule to clock this signer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have created this test, and it worked:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Created a new custom BIOC rule in Detection Rules - BIOC&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1702308462689.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55810i7302176FAE09F3B7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmazzeo_0-1702308462689.png" alt="jmazzeo_0-1702308462689.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;With right click I have assigned the rule to a restrictions profile.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_1-1702308508528.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55811i3AA7B3B1DE5A53D8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmazzeo_1-1702308508528.png" alt="jmazzeo_1-1702308508528.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;I have enabled the "Custom Prevention Rules" action in the assigned Restrictions Profile, and the rule appears there.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_2-1702308558982.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55812iEEC630A8350A69F5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmazzeo_2-1702308558982.png" alt="jmazzeo_2-1702308558982.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The downloaded Notepad++ is blocked in execution. This also can work in the extraction point, the exe uses the same signature name.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_3-1702308673984.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55813i80659D1F6D288E01/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmazzeo_3-1702308673984.png" alt="jmazzeo_3-1702308673984.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this works for you, mark this post as the solution. Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 15:32:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/portableapps-block-all/m-p/569295#M5696</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2023-12-11T15:32:05Z</dc:date>
    </item>
  </channel>
</rss>

