<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Legacy agent exception and Disable prevention rule in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception-and-disable-prevention-rule/m-p/586339#M6654</link>
    <description>&lt;P&gt;Thanks JM, your response is appreciated.&lt;/P&gt;</description>
    <pubDate>Thu, 09 May 2024 21:55:53 GMT</pubDate>
    <dc:creator>DannyMulheran</dc:creator>
    <dc:date>2024-05-09T21:55:53Z</dc:date>
    <item>
      <title>Legacy agent exception and Disable prevention rule</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception-and-disable-prevention-rule/m-p/586253#M6648</link>
      <description>&lt;P&gt;What is the difference between Legacy agent exception and Disable prevention rules?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This was asked in another discussion but the answer does not resolve the question asked (&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exception-and-exclusion-tips-amp-trick-best-practices/td-p/569675" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exception-and-exclusion-tips-amp-trick-best-practices/td-p/569675&lt;/A&gt; )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Danny&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 04:51:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception-and-disable-prevention-rule/m-p/586253#M6648</guid>
      <dc:creator>DannyMulheran</dc:creator>
      <dc:date>2024-05-09T04:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy agent exception and Disable prevention rule</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception-and-disable-prevention-rule/m-p/586276#M6649</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/150849"&gt;@DannyMulheran&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-a-Disable-Prevention-Rule" target="_self"&gt;Disable Prevention Rules&lt;/A&gt; applies to agents only from version 7.9 and above.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1715256308817.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59592i49EB6D8646E02ED7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmazzeo_0-1715256308817.png" alt="jmazzeo_0-1715256308817.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-a-Legacy-Exception-Rule" target="_self"&gt;Legacy Agent Exceptions&lt;/A&gt; also applies to older agent versions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 12:08:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception-and-disable-prevention-rule/m-p/586276#M6649</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-05-09T12:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy agent exception and Disable prevention rule</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception-and-disable-prevention-rule/m-p/586303#M6652</link>
      <description>&lt;P&gt;Disable prevention rules are more granular compared to legacy agent exceptions.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Legacy agent exceptions Target the hole module like pe dll examination where as disable prevention rules would Target specific protections within that..like we can do wildfire detection, wildfire post detection, local analysis etc..&lt;/P&gt;
&lt;P&gt;Disable prevention rules generate an alert even after allowing the activities where as legacy agent exceptions mostly don't generate alerts and allow a process to run.(E.g global behavior protection based legacy exception or credential protection module related ones generate alerts and other PE dll examination module based legacy agent exceptions don't generate alerts.&lt;/P&gt;
&lt;P&gt;That's all I can remember for now &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 17:04:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception-and-disable-prevention-rule/m-p/586303#M6652</guid>
      <dc:creator>Fm12345</dc:creator>
      <dc:date>2024-05-09T17:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy agent exception and Disable prevention rule</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception-and-disable-prevention-rule/m-p/586338#M6653</link>
      <description>&lt;P&gt;Thanks, really appreciate the reply.&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 21:54:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception-and-disable-prevention-rule/m-p/586338#M6653</guid>
      <dc:creator>DannyMulheran</dc:creator>
      <dc:date>2024-05-09T21:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy agent exception and Disable prevention rule</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception-and-disable-prevention-rule/m-p/586339#M6654</link>
      <description>&lt;P&gt;Thanks JM, your response is appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 21:55:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception-and-disable-prevention-rule/m-p/586339#M6654</guid>
      <dc:creator>DannyMulheran</dc:creator>
      <dc:date>2024-05-09T21:55:53Z</dc:date>
    </item>
  </channel>
</rss>

