<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Exclusion process cortex?! in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exclusion-process-cortex/m-p/579136#M6236</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;How can I create an exclusion in &lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;to stop it from scanning a specific executable??&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;We have a critical software in our company, and we've noticed that Cortex is constantly analyzing it, causing the machine high CPU and MEM.&lt;BR /&gt;&lt;BR /&gt;How can we exclude this file from the analysis? &lt;SPAN&gt;We want to maintain protections such as Ransomware, just excluding the process monitoring.&lt;BR /&gt;It's possible?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Mar 2024 13:04:41 GMT</pubDate>
    <dc:creator>tlmarques</dc:creator>
    <dc:date>2024-03-04T13:04:41Z</dc:date>
    <item>
      <title>Exclusion process cortex?!</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exclusion-process-cortex/m-p/579136#M6236</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;How can I create an exclusion in &lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;to stop it from scanning a specific executable??&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;We have a critical software in our company, and we've noticed that Cortex is constantly analyzing it, causing the machine high CPU and MEM.&lt;BR /&gt;&lt;BR /&gt;How can we exclude this file from the analysis? &lt;SPAN&gt;We want to maintain protections such as Ransomware, just excluding the process monitoring.&lt;BR /&gt;It's possible?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 13:04:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exclusion-process-cortex/m-p/579136#M6236</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-03-04T13:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: Exclusion process cortex?!</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exclusion-process-cortex/m-p/579141#M6237</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need to create a Disable Prevention Rule.&lt;/P&gt;
&lt;P&gt;Go to Settings - Exceptions Configuration - Disable Prevention Rules, create a new one, set the name and fill the parameters:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Set the target properties, folder location and executable name, command line, or you can use the signer. Only one is enough.&lt;/P&gt;
&lt;P&gt;- Module: try with the Local Analysis and check how it goes, if it is an in-house software it is probably "Unknown" for Wildfire and the agent tries to analyze it locally, consuming CPU and RAM to do it.&lt;/P&gt;
&lt;P&gt;- Scope: select the applied profile to the Endpoints with the issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1709558611756.png" style="width: 741px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58032iFEAE538303E9D015/image-dimensions/741x526/is-moderation-mode/true?v=v2" width="741" height="526" role="button" title="jmazzeo_0-1709558611756.png" alt="jmazzeo_0-1709558611756.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also go to Detecion Rules - IOC and add an IOC with the application path and/or executable hash (ni the "Type" field):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_1-1709559311916.png" style="width: 371px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58033iD98BBC1322DC53FE/image-dimensions/371x473/is-moderation-mode/true?v=v2" width="371" height="473" role="button" title="jmazzeo_1-1709559311916.png" alt="jmazzeo_1-1709559311916.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know how it goes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post solved your question, please mark it as the solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 13:36:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exclusion-process-cortex/m-p/579141#M6237</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-03-04T13:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: Exclusion process cortex?!</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exclusion-process-cortex/m-p/1223856#M8054</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I found your response very insightful and helpful. I just have a question. How can I know which module to select when creating that prevention profile? In my case, it's also an in-house developed software which its developer reported performance issues. For example, should I select "Wildfire" and "Behavioral Threat Protection" together, or just one of them suffices? How can I find which module(s) is/are more relevant to this performance issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR,&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 08:19:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exclusion-process-cortex/m-p/1223856#M8054</guid>
      <dc:creator>Arman_Zaheri</dc:creator>
      <dc:date>2025-03-14T08:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: Exclusion process cortex?!</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exclusion-process-cortex/m-p/1233018#M8508</link>
      <description>&lt;P&gt;In selecting the scope you are given the choice of Global or Exceptions Profile.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Kahlilp_0-1751446155329.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68270iD5F2309113EA216D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Kahlilp_0-1751446155329.png" alt="Kahlilp_0-1751446155329.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;However when you go to the Exceptions profile, the folder/path I specified is not in any of the modules there. If I go to the Malware Profile for example (because I selected Wildfire in the choices -- it also doesn't show up in any of the malware profile -- because the scope is Exception Profile.)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In short, where do I confirm that the folder/path I specified in the Disable Prevention Rule is in place -- surely its not in any of the Exception profiles.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 08:51:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exclusion-process-cortex/m-p/1233018#M8508</guid>
      <dc:creator>Kahlilp</dc:creator>
      <dc:date>2025-07-02T08:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: Exclusion process cortex?!</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exclusion-process-cortex/m-p/1233026#M8510</link>
      <description>&lt;P&gt;you need to add the exception profiles to the policy first. Once the policy appears...&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tlmarques_0-1751457243703.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68272i833503D23B2C8163/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tlmarques_0-1751457243703.png" alt="tlmarques_0-1751457243703.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 11:55:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exclusion-process-cortex/m-p/1233026#M8510</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2025-07-02T11:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: Exclusion process cortex?!</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exclusion-process-cortex/m-p/1243800#M8915</link>
      <description>&lt;P&gt;What is the difference between a process exception and a operational agent exception? Is it that on process exception you select which module one wants to exclude it from.&amp;nbsp;&lt;BR /&gt;Is there any documentation anywhere all these different exceptions are described in detail and when they should be used?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Also how does it differ from a&amp;nbsp;&lt;SPAN&gt;Disable Prevention Rules.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Mike.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 08:13:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exclusion-process-cortex/m-p/1243800#M8915</guid>
      <dc:creator>SEKKDK</dc:creator>
      <dc:date>2025-12-12T08:13:36Z</dc:date>
    </item>
  </channel>
</rss>

