<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Application WhiteListing in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/application-whitelisting/m-p/589062#M6806</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1551422421"&gt;@jia_xuan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for providing the information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create an Alert Exclusion and add that to the profile instead of Global. Or take the execution script and create the Custom Prevention Rule or add it to Legacy agent exception.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once it is done, retrieve the alert data and open a TAC to check the reputation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jun 2024 10:49:17 GMT</pubDate>
    <dc:creator>aspatil</dc:creator>
    <dc:date>2024-06-07T10:49:17Z</dc:date>
    <item>
      <title>Application WhiteListing</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/application-whitelisting/m-p/588895#M6793</link>
      <description>&lt;P&gt;I have an application that needs whitelisting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Actions Done:&lt;/P&gt;
&lt;P&gt;Add to Allow List&lt;/P&gt;
&lt;P&gt;Add to Malware Profile, under specific module that triggered alert/incident.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is still showing up in incidents when executed. Any idea what could be going on?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 03:01:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/application-whitelisting/m-p/588895#M6793</guid>
      <dc:creator>jia_xuan</dc:creator>
      <dc:date>2024-06-06T03:01:57Z</dc:date>
    </item>
    <item>
      <title>Re: Application WhiteListing</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/application-whitelisting/m-p/588897#M6794</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1551422421"&gt;@jia_xuan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out on Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could&amp;nbsp; you please confirm below:&lt;/P&gt;
&lt;P&gt;1. Which Module is trigger alert?&lt;/P&gt;
&lt;P&gt;2. What is the detection source, is it BPT, Local Analysis or Wildfire?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 06:05:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/application-whitelisting/m-p/588897#M6794</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-06-06T06:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: Application WhiteListing</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/application-whitelisting/m-p/589017#M6805</link>
      <description>&lt;DIV id="bodyDisplay_1" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;1) Credential Gathering Protection&lt;/P&gt;
&lt;P&gt;2) XDR Agent, Wildfire has marked detection benign.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 07 Jun 2024 00:31:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/application-whitelisting/m-p/589017#M6805</guid>
      <dc:creator>jia_xuan</dc:creator>
      <dc:date>2024-06-07T00:31:14Z</dc:date>
    </item>
    <item>
      <title>Re: Application WhiteListing</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/application-whitelisting/m-p/589062#M6806</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1551422421"&gt;@jia_xuan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for providing the information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create an Alert Exclusion and add that to the profile instead of Global. Or take the execution script and create the Custom Prevention Rule or add it to Legacy agent exception.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once it is done, retrieve the alert data and open a TAC to check the reputation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 10:49:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/application-whitelisting/m-p/589062#M6806</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-06-07T10:49:17Z</dc:date>
    </item>
  </channel>
</rss>

