<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: On-write Protection is disabled by default in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-protection-is-disabled-by-default/m-p/584494#M6553</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428"&gt;@jmazzeo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When one reads the name of the module, normally comes to mind every kind of file writing events, not only the executables or scripts. Couldn't find the exact info about it in the docus. Do you have a link to the source of this info, where perhaps I can get more&amp;nbsp; also on other modules?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advence.&lt;/P&gt;</description>
    <pubDate>Mon, 22 Apr 2024 13:51:16 GMT</pubDate>
    <dc:creator>AbdBgc</dc:creator>
    <dc:date>2024-04-22T13:51:16Z</dc:date>
    <item>
      <title>On-write Protection is disabled by default</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-protection-is-disabled-by-default/m-p/583820#M6513</link>
      <description>&lt;P&gt;Hi everyone,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just wondering how's the performance or resource is impacted when this protection is on, i bet it would have certain impact as this is "Disabled" by default. or any other concerns if ON?&lt;/P&gt;
&lt;P&gt;Any experience to share?&lt;/P&gt;
&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 04:39:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-protection-is-disabled-by-default/m-p/583820#M6513</guid>
      <dc:creator>SeanDeHarris</dc:creator>
      <dc:date>2024-04-16T04:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: On-write Protection is disabled by default</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-protection-is-disabled-by-default/m-p/584058#M6527</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184443"&gt;@SeanDeHarris&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The on-write protection should not generate too much impact on the endpoints, because this module only starts a scan when the written file is an executable or a script. The &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/File-Analysis-and-Protection-Flow" target="_self"&gt;scan workflow&lt;/A&gt; is the same when a file is executed, first it will ask to Wildfire about the reputation, and if the reputation is good, no other scan will be executed.&lt;/P&gt;
&lt;P&gt;If you want to test if first, I'll recommend you to create a &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Set-up-malware-security-profiles" target="_self"&gt;new malware profile&lt;/A&gt;, enable this feature, and assign it to a group of endpoints to monitor the performance behavior.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 15:35:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-protection-is-disabled-by-default/m-p/584058#M6527</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-04-17T15:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: On-write Protection is disabled by default</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-protection-is-disabled-by-default/m-p/584494#M6553</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428"&gt;@jmazzeo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When one reads the name of the module, normally comes to mind every kind of file writing events, not only the executables or scripts. Couldn't find the exact info about it in the docus. Do you have a link to the source of this info, where perhaps I can get more&amp;nbsp; also on other modules?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advence.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2024 13:51:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-protection-is-disabled-by-default/m-p/584494#M6553</guid>
      <dc:creator>AbdBgc</dc:creator>
      <dc:date>2024-04-22T13:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: On-write Protection is disabled by default</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-protection-is-disabled-by-default/m-p/584673#M6570</link>
      <description>&lt;P&gt;This is what we can share about the On-Write file protection file types and some other useful information:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- File types: DLL, PE&amp;nbsp; and Macro&lt;/P&gt;
&lt;P&gt;- Exceptions: add affected path to the blocking module.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2024 20:46:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-protection-is-disabled-by-default/m-p/584673#M6570</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-12-30T20:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: On-write Protection is disabled by default</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-protection-is-disabled-by-default/m-p/584731#M6577</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428"&gt;@jmazzeo&lt;/a&gt;&amp;nbsp;, this is helpful.&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as I see, even as admin I have only the option to turn it on or off, Enabled/Disabled, in Malware Prevention Profile from the Console. So, no option to use this protection type in monitoring only mode (no "Report" only option)&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;"&gt;if enabled&lt;/STRONG&gt;&lt;SPAN&gt; it will detect and &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;"&gt;prevent in any case.&lt;/STRONG&gt;&lt;SPAN&gt; Is that correct?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 05:56:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-protection-is-disabled-by-default/m-p/584731#M6577</guid>
      <dc:creator>AbdBgc</dc:creator>
      <dc:date>2024-04-24T05:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: On-write Protection is disabled by default</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-protection-is-disabled-by-default/m-p/584783#M6582</link>
      <description>&lt;P&gt;That toggle is to enable the ability to send the written files to analysis. The actions are made by the usual modules as is mentioned in the last bullet on the screenshot.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 12:42:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-protection-is-disabled-by-default/m-p/584783#M6582</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-04-24T12:42:58Z</dc:date>
    </item>
  </channel>
</rss>

