<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allowing child process from parent process in Cortex XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/allowing-child-process-from-parent-process-in-cortex-xdr/m-p/586010#M6645</link>
    <description>&lt;P&gt;Hi, I am also looking for inputs on same situation. Did you already receive any response for above query ?&lt;/P&gt;</description>
    <pubDate>Tue, 07 May 2024 14:31:42 GMT</pubDate>
    <dc:creator>MadhuriN</dc:creator>
    <dc:date>2024-05-07T14:31:42Z</dc:date>
    <item>
      <title>Allowing child process from parent process in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/allowing-child-process-from-parent-process-in-cortex-xdr/m-p/342239#M232</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to allow a legitimate parent process to create a legitimate child process on Cortex XDR that is being blocked due to "Suspicious Process Creation"? In my case, I whitelisted the child process but the block continues. I do not want to whitelist the parent process as this may allow malware into our environment someday.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I remember version 4.1 of Traps allowing this under Child Process Protection (I think was the name). For example "ParentProcess.exe -&amp;gt;spawns-&amp;gt; ChildProcess.exe : Allow". I looked into the exception profile, but it only allows me to create an exception for just one specific process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If anyone has an idea of if/how to accomplish this with Cortex XDR, please let me know! Thank you, stay safe.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 15:43:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/allowing-child-process-from-parent-process-in-cortex-xdr/m-p/342239#M232</guid>
      <dc:creator>oburgos</dc:creator>
      <dc:date>2020-08-05T15:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing child process from parent process in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/allowing-child-process-from-parent-process-in-cortex-xdr/m-p/342335#M233</link>
      <description>&lt;P&gt;Hi, I believe this may be what you are looking for:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Under Endpoints go to Policy Management&lt;/LI&gt;&lt;LI&gt;Then select Profiles on the left under the Prevention heading&lt;/LI&gt;&lt;LI&gt;Find your active Malware profile and right-click and Edit&lt;/LI&gt;&lt;LI&gt;Scroll down to&amp;nbsp;&lt;SPAN&gt;Malicious Child Process Protection&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;You will then find a whitelist option to do a combo of the parent and child process along with any specific parameters&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 22:38:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/allowing-child-process-from-parent-process-in-cortex-xdr/m-p/342335#M233</guid>
      <dc:creator>ajrechk</dc:creator>
      <dc:date>2020-08-05T22:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing child process from parent process in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/allowing-child-process-from-parent-process-in-cortex-xdr/m-p/578051#M6120</link>
      <description>&lt;P&gt;&amp;nbsp;Heloo&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1082"&gt;@ajrechk&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;According to:&lt;/P&gt;
&lt;P&gt;Application information:&lt;BR /&gt;Application name:  Windows Explorer&lt;BR /&gt;Application version:  10.0.22621.3007&lt;BR /&gt;Application publisher:  Microsoft Corporation&lt;BR /&gt;Process ID:  20676&lt;BR /&gt;Application location:  C:\Windows\explorer.exe&lt;BR /&gt;Command line:  C:\WINDOWS\Explorer.EXE&lt;BR /&gt;File origin:  Hard drive on this computer&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Target application information:&lt;BR /&gt;Application name:  Java(TM) Platform SE binary&lt;BR /&gt;Application version:  21.0.2.0&lt;BR /&gt;Application publisher:  Oracle Corporation&lt;BR /&gt;Process ID:  2432&lt;BR /&gt;Application location:  C:\Program Files\Java\jdk-21\bin\javaw.exe&lt;BR /&gt;Command line:  "C:\Program Files\Java\jdk-21\bin\javaw.exe" -jar "C:\Users\ayxanp\AppData\Local\Temp\961644af-8259-4735-a751-8b545a44ed02_apache-jmeter-5.6.3.tgz.d02\apache-jmeter-5.6.3\bin\ApacheJMeter.jar"&amp;nbsp;&lt;BR /&gt;File origin:  Hard drive on this computer&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Prevention information:&lt;BR /&gt;Prevention date:  Thursday, February 22, 2024&lt;BR /&gt;Prevention time:  11:30:43&lt;BR /&gt;OS version:  10.0.22631.2.0.0.256.1&lt;BR /&gt;Component:  Child Process Protection&lt;BR /&gt;Status code:  80400057&lt;BR /&gt;Prevention description:  Suspicious process creation detected&lt;BR /&gt;Additional information 1:  explorer.exe&lt;BR /&gt;Additional information 2:  C:\Program Files\Java\jdk-21\bin\javaw.exe&lt;BR /&gt;Additional information 3:  -jar "C:\Users\ayxanp\AppData\Local\Temp\961644af-8259-4735-a751-8b545a44ed02_apache-jmeter-5.6.3.tgz.d02\apache-jmeter-5.6.3\bin\ApacheJMeter.jar"&amp;nbsp;&lt;BR /&gt;Additional information 4:  ChildProcessPattern: *\javaw.exe, Flag: D, CommandLineRegex: ((?i)([-/]jar\s+\"?((\Q%temp%\E)|(\Q%templong%\E)|(\Q%SystemDrive%\E\\Users\\.*\\temp)|(\Q%SystemDrive%\E\\docume.*\\temp))\\.*))&lt;BR /&gt;&lt;BR /&gt;What should I write to these fields:&lt;BR /&gt;&lt;SPAN&gt;I need to create legacy agent exception for that. When I go to this page, I choose "&lt;/SPAN&gt;&lt;SPAN&gt;Malware &amp;gt; Malicious Child Process Protection" as module and it requires me to fill three things which are:&lt;BR /&gt;1.&amp;nbsp;Parent Process Name&lt;BR /&gt;2.&amp;nbsp;Child Process Name&lt;BR /&gt;3.&amp;nbsp;Child Process Command Line Params&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 11:10:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/allowing-child-process-from-parent-process-in-cortex-xdr/m-p/578051#M6120</guid>
      <dc:creator>JahidAliyev</dc:creator>
      <dc:date>2024-02-22T11:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing child process from parent process in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/allowing-child-process-from-parent-process-in-cortex-xdr/m-p/586010#M6645</link>
      <description>&lt;P&gt;Hi, I am also looking for inputs on same situation. Did you already receive any response for above query ?&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 14:31:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/allowing-child-process-from-parent-process-in-cortex-xdr/m-p/586010#M6645</guid>
      <dc:creator>MadhuriN</dc:creator>
      <dc:date>2024-05-07T14:31:42Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing child process from parent process in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/allowing-child-process-from-parent-process-in-cortex-xdr/m-p/589785#M6829</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/274228"&gt;@JahidAliyev&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Did you receive any update on the issue, I'm also facing the same issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 11:42:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/allowing-child-process-from-parent-process-in-cortex-xdr/m-p/589785#M6829</guid>
      <dc:creator>Vijisaga</dc:creator>
      <dc:date>2024-06-18T11:42:28Z</dc:date>
    </item>
  </channel>
</rss>

