<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XDR on-write exclusions in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-on-write-exclusions/m-p/579916#M6300</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428"&gt;@jmazzeo&lt;/a&gt;&amp;nbsp;how i can&amp;nbsp;&lt;SPAN&gt;check which&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;module&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;is blocking ??&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2024 11:55:43 GMT</pubDate>
    <dc:creator>tlmarques</dc:creator>
    <dc:date>2024-03-11T11:55:43Z</dc:date>
    <item>
      <title>XDR on-write exclusions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-on-write-exclusions/m-p/579659#M6290</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Is it possible to exclude certain executables and their hashes from on-write protection on &lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;??&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 14:33:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-on-write-exclusions/m-p/579659#M6290</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-03-07T14:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: XDR on-write exclusions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-on-write-exclusions/m-p/579688#M6291</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is no possibility to create an exclusion for the On-Write protection itself. This module detects when a new file is writed on disk, and then starts the usual &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/File-Analysis-and-Protection-Flow" target="_self"&gt;file analysis flow&lt;/A&gt;:&lt;/P&gt;
&lt;DIV id="tinyMceEditor_5d1b7eacd42050jmazzeo_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_2-1709833376722.png" style="width: 548px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58154i638A60AE57C953D3/image-dimensions/548x294/is-moderation-mode/true?v=v2" width="548" height="294" role="button" title="jmazzeo_2-1709833376722.png" alt="jmazzeo_2-1709833376722.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then you have two options:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;If a file is blocked and you need to allow it, check which &lt;STRONG&gt;module&lt;/STRONG&gt; is blocking it and then create the exception for that module under Settings - Exceptions Configuration.&lt;/LI&gt;
&lt;LI&gt;Create an Administrative Hash exception, going to&amp;nbsp;Settings - Exceptions Configuration -&amp;nbsp;Disable Prevention Rules, and adding a new rule with the file hash and selecting "Hash Control" as the module.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_3-1709833513289.png" style="width: 532px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58155i212E93B853C71CB9/image-dimensions/532x407/is-moderation-mode/true?v=v2" width="532" height="407" role="button" title="jmazzeo_3-1709833513289.png" alt="jmazzeo_3-1709833513289.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please let me know how it goes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 17:47:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-on-write-exclusions/m-p/579688#M6291</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-03-07T17:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: XDR on-write exclusions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-on-write-exclusions/m-p/579916#M6300</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428"&gt;@jmazzeo&lt;/a&gt;&amp;nbsp;how i can&amp;nbsp;&lt;SPAN&gt;check which&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;module&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;is blocking ??&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2024 11:55:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-on-write-exclusions/m-p/579916#M6300</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-03-11T11:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: XDR on-write exclusions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-on-write-exclusions/m-p/621637#M7432</link>
      <description>&lt;P&gt;You can check in causality chain. Information Overview&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2024 05:00:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-on-write-exclusions/m-p/621637#M7432</guid>
      <dc:creator>P.Ghule</dc:creator>
      <dc:date>2024-11-18T05:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: XDR on-write exclusions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-on-write-exclusions/m-p/627694#M7445</link>
      <description>&lt;P&gt;Looks like I missed this reply...&lt;/P&gt;
&lt;P&gt;You can do it as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/651576993"&gt;@P.Ghule&lt;/a&gt;&amp;nbsp;mentions, or by adding the "Module" column in the Alerts View.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1732036236038.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/64118iAC03DAF3E1687143/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jmazzeo_0-1732036236038.png" alt="jmazzeo_0-1732036236038.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 17:10:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-on-write-exclusions/m-p/627694#M7445</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-11-19T17:10:45Z</dc:date>
    </item>
  </channel>
</rss>

