<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR whitelisting in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-whitelisting/m-p/400844#M671</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/170102"&gt;@MCereda&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You still have Child Process Protection, Office files with Macros and Ransomware.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to point out that active whitelisting is &lt;STRONG&gt;NOT&lt;/STRONG&gt; really recommended except for&amp;nbsp;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;Portable Executable and DLL Examination" as Local Analysis could indeed block legit applications, and it could take WF up to 10-15 minutes to provide a benign verdict.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The other modules have different kind of protections and I would only recommend whitelisting whenever there is a false positive alert.&lt;BR /&gt;&lt;BR /&gt;You need to monitor your incidents/alerts and see which modules are blocking your "legit" applications.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Apr 2021 10:08:10 GMT</pubDate>
    <dc:creator>fmoixsante</dc:creator>
    <dc:date>2021-04-21T10:08:10Z</dc:date>
    <item>
      <title>Cortex XDR whitelisting</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-whitelisting/m-p/400835#M670</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have been asked to whitelist a specified folder in order to disable any kind of real-time checks and analysis made by Cortex XDR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So, we added the aforementioned folder in the allow lists of "&lt;/SPAN&gt;&lt;SPAN&gt;Portable Executable and DLL Examination" and "Behavioral Threat Protection" sections&lt;/SPAN&gt;&lt;SPAN&gt; in "Malware profile" configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;With this kind of configuration enabled what are Cortex XDR real-time checks that remain active?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 09:27:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-whitelisting/m-p/400835#M670</guid>
      <dc:creator>MCereda</dc:creator>
      <dc:date>2021-04-21T09:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR whitelisting</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-whitelisting/m-p/400844#M671</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/170102"&gt;@MCereda&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You still have Child Process Protection, Office files with Macros and Ransomware.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to point out that active whitelisting is &lt;STRONG&gt;NOT&lt;/STRONG&gt; really recommended except for&amp;nbsp;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;Portable Executable and DLL Examination" as Local Analysis could indeed block legit applications, and it could take WF up to 10-15 minutes to provide a benign verdict.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The other modules have different kind of protections and I would only recommend whitelisting whenever there is a false positive alert.&lt;BR /&gt;&lt;BR /&gt;You need to monitor your incidents/alerts and see which modules are blocking your "legit" applications.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 10:08:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-whitelisting/m-p/400844#M671</guid>
      <dc:creator>fmoixsante</dc:creator>
      <dc:date>2021-04-21T10:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR whitelisting</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-whitelisting/m-p/400884#M674</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/64736"&gt;@fmoixsante&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;thank you for the answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As we have been asked us to temporarily disable any kind of real-time checks and analysis made by Cortex XDR on a specified folder in order to test a performance issue, do you know how to completely disable Cortex XDR features for a single folder?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 12:03:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-whitelisting/m-p/400884#M674</guid>
      <dc:creator>MCereda</dc:creator>
      <dc:date>2021-04-21T12:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR whitelisting</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-whitelisting/m-p/400888#M676</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/170102"&gt;@MCereda&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can whitelist folders for almost every malware module, except for Ransomware and&amp;nbsp;Password Theft Protection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the Exploit module, disabling protections for a single folder is not supported as far as I know. As of now, there is no way to do that directly from the Exploit module. I would suggest contacting TAC and ask them if a Support Exception (SUEX) would be able to achieve what you want to do.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 12:09:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-whitelisting/m-p/400888#M676</guid>
      <dc:creator>fmoixsante</dc:creator>
      <dc:date>2021-04-21T12:09:18Z</dc:date>
    </item>
  </channel>
</rss>

