<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Potentially Dangerous Tool Alert in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/potentially-dangerous-tool-alert/m-p/583878#M6514</link>
    <description>&lt;P&gt;This seems to do the trick. Thank you for your help.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Apr 2024 12:09:51 GMT</pubDate>
    <dc:creator>aholdt</dc:creator>
    <dc:date>2024-04-16T12:09:51Z</dc:date>
    <item>
      <title>Potentially Dangerous Tool Alert</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/potentially-dangerous-tool-alert/m-p/583706#M6505</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;&lt;BR /&gt;Cortex has started blocking a legitimate tool we use: certify.exe, which is part of Certify The Web, that we use to automate certificate renewal from Lets Encrypt.&lt;BR /&gt;&lt;BR /&gt;I have not seen this before. Is there anyway to whitelist this tool?&lt;BR /&gt;The precise alert name is: "&lt;SPAN&gt;Potentially Dangerous Tool - 1827272396", but googling this does not give me much.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 08:18:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/potentially-dangerous-tool-alert/m-p/583706#M6505</guid>
      <dc:creator>aholdt</dc:creator>
      <dc:date>2024-04-15T08:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: Potentially Dangerous Tool Alert</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/potentially-dangerous-tool-alert/m-p/583752#M6508</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/295100"&gt;@aholdt&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;If after analysis you have found the tool is safe and legitimate then you can create an exception for it. But while creating exception make sure to create a very granular exception. Firstly you need to identify the security module that has blocked the tool, to do that please check the "Module" field in alerts table. Once you have the module then you can create a legacy exception based on software name and location. Also you can target this exception to particular profile which applies to group of endpoints on which you are going to use this tool.&lt;/P&gt;
&lt;P&gt;Reference-&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Add-a-Legacy-Exception-Rule" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Add-a-Legacy-Exception-Rule&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please c&lt;SPAN&gt;lick&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;to acknowledge that the answer to your question has been provided.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 16:42:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/potentially-dangerous-tool-alert/m-p/583752#M6508</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2024-04-15T16:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: Potentially Dangerous Tool Alert</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/potentially-dangerous-tool-alert/m-p/583878#M6514</link>
      <description>&lt;P&gt;This seems to do the trick. Thank you for your help.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 12:09:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/potentially-dangerous-tool-alert/m-p/583878#M6514</guid>
      <dc:creator>aholdt</dc:creator>
      <dc:date>2024-04-16T12:09:51Z</dc:date>
    </item>
  </channel>
</rss>

