<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding file and folder exclusions in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/adding-file-and-folder-exclusions/m-p/597899#M7183</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We are implementing FSlogix profiles in our environment. Is the solution you provide here enough? If I need to do something else or different, let me know.&lt;/P&gt;
&lt;P&gt;This is the exclusion that I need to add per Microsoft documentation:&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="file--folder-exclusions" class="heading-anchor"&gt;File / folder exclusions&lt;/H3&gt;
&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;%TEMP%\*\*.VHD&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;%TEMP%\*\*.VHDX&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;%Windir%\TEMP\*\*.VHD&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;%Windir%\TEMP\*\*.VHDX&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;\\server-name\share-name\*\*.VHD&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;\\server-name\share-name\*\*.VHD.lock&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;\\server-name\share-name\*\*.VHD.meta&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;\\server-name\share-name\*\*.VHD.metadata&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;\\server-name\share-name\*\*.VHDX&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;\\server-name\share-name\*\*.VHDX.lock&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;\\server-name\share-name\*\*.VHDX.meta&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;\\server-name\share-name\*\*.VHDX.metadata&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cloud Cache specific exclusions&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;%ProgramData%\FSLogix\Cache\*&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(&lt;STRONG&gt;folder and files&lt;/STRONG&gt;)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;%ProgramData%\FSLogix\Proxy\*&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(&lt;STRONG&gt;folder and files&lt;/STRONG&gt;)&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://learn.microsoft.com/en-us/fslogix/overview-prerequisites#configure-antivirus-file-and-folder-exclusions" target="_blank"&gt;Prerequisites for FSLogix - FSLogix | Microsoft Learn&lt;/A&gt;&lt;BR /&gt;Thank you in advance for your guidance.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Sep 2024 14:50:13 GMT</pubDate>
    <dc:creator>J.Bravo779077</dc:creator>
    <dc:date>2024-09-16T14:50:13Z</dc:date>
    <item>
      <title>Adding file and folder exclusions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/adding-file-and-folder-exclusions/m-p/562296#M5375</link>
      <description>&lt;P&gt;We have&amp;nbsp; a security camera server that's been throwing out low memory resource messages and the company that provides the software claims that Cortex XDR endpoint client is causing memory leaks. There are no incidents being triggered by this server and the memory usage of Cortex is always under 1GB of memory. They have provided documentation that appears to be geared more toward traditional antivirus software to add folder and file exceptions from the software. I don't see in the XDR control console a place for me to make these exceptions unless there was an incident or to allow list a vendor or hash. Does this seem like they're grasping for something to be the issue or can anyone help guide me on how to add these exceptions. Below is the document they provided to help understand what they're asking of us to do.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.avigilon.com/s/article/ACC-Files-and-Folders-to-be-Added-to-An-Antivirus-Exclusion-List?language=en_US" target="_blank"&gt;https://support.avigilon.com/s/article/ACC-Files-and-Folders-to-be-Added-to-An-Antivirus-Exclusion-List?language=en_US&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 17:22:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/adding-file-and-folder-exclusions/m-p/562296#M5375</guid>
      <dc:creator>JLawrence-Serra</dc:creator>
      <dc:date>2023-10-18T17:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: Adding file and folder exclusions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/adding-file-and-folder-exclusions/m-p/562308#M5376</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/323593"&gt;@JLawrence-Serra&lt;/a&gt;, thanks for reaching the Live Community.&lt;/P&gt;
&lt;P&gt;You can create exceptions rules to avoid files or folder for being scanned by the XDR Agent modules.&lt;/P&gt;
&lt;P&gt;You need to create a "Disable Prevention Rule", this is located at&amp;nbsp;&lt;STRONG&gt;&lt;SPAN class="guimenuitem"&gt;Settings&lt;/SPAN&gt;&amp;nbsp;→&amp;nbsp;&lt;SPAN class="guimenuitem"&gt;Exception Configuration&lt;/SPAN&gt;&amp;nbsp;→&amp;nbsp;&lt;SPAN class="guimenuitem"&gt;Disable Prevention Rules&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the official doc:&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-a-Disable-Prevention-Rule" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-a-Disable-Prevention-Rule&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I recommend creating the rule and apply this only to the Profile that is assigned to this endpoints.&lt;/P&gt;
&lt;P&gt;When you define the rule, note that you can use wildcards for the folder definitions. In your case, you will need to create more than one rule to cover all the required folders.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1697653610262.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54526i2FB5CFADA9B2087F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmazzeo_0-1697653610262.png" alt="jmazzeo_0-1697653610262.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think this can solve your inquiry.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 18:28:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/adding-file-and-folder-exclusions/m-p/562308#M5376</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2023-10-18T18:28:43Z</dc:date>
    </item>
    <item>
      <title>Re: Adding file and folder exclusions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/adding-file-and-folder-exclusions/m-p/562310#M5377</link>
      <description>&lt;P&gt;Thank you very much for your help! That helped solve my problem! I appreciate the details you provided in the screen shot.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 18:56:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/adding-file-and-folder-exclusions/m-p/562310#M5377</guid>
      <dc:creator>JLawrence-Serra</dc:creator>
      <dc:date>2023-10-18T18:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: Adding file and folder exclusions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/adding-file-and-folder-exclusions/m-p/597899#M7183</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We are implementing FSlogix profiles in our environment. Is the solution you provide here enough? If I need to do something else or different, let me know.&lt;/P&gt;
&lt;P&gt;This is the exclusion that I need to add per Microsoft documentation:&lt;/P&gt;
&lt;DIV class="heading-wrapper" data-heading-level="h3"&gt;
&lt;H3 id="file--folder-exclusions" class="heading-anchor"&gt;File / folder exclusions&lt;/H3&gt;
&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;%TEMP%\*\*.VHD&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;%TEMP%\*\*.VHDX&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;%Windir%\TEMP\*\*.VHD&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;%Windir%\TEMP\*\*.VHDX&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;\\server-name\share-name\*\*.VHD&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;\\server-name\share-name\*\*.VHD.lock&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;\\server-name\share-name\*\*.VHD.meta&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;\\server-name\share-name\*\*.VHD.metadata&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;\\server-name\share-name\*\*.VHDX&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;\\server-name\share-name\*\*.VHDX.lock&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;\\server-name\share-name\*\*.VHDX.meta&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;\\server-name\share-name\*\*.VHDX.metadata&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cloud Cache specific exclusions&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;%ProgramData%\FSLogix\Cache\*&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(&lt;STRONG&gt;folder and files&lt;/STRONG&gt;)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;%ProgramData%\FSLogix\Proxy\*&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(&lt;STRONG&gt;folder and files&lt;/STRONG&gt;)&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://learn.microsoft.com/en-us/fslogix/overview-prerequisites#configure-antivirus-file-and-folder-exclusions" target="_blank"&gt;Prerequisites for FSLogix - FSLogix | Microsoft Learn&lt;/A&gt;&lt;BR /&gt;Thank you in advance for your guidance.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2024 14:50:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/adding-file-and-folder-exclusions/m-p/597899#M7183</guid>
      <dc:creator>J.Bravo779077</dc:creator>
      <dc:date>2024-09-16T14:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: Adding file and folder exclusions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/adding-file-and-folder-exclusions/m-p/598422#M7205</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1517869145"&gt;@J.Bravo779077&lt;/a&gt;, we don't recommend to add exceptions before installing the agent. Those recommendations are for legacy antivirus solutions, any modern EDR solution like XDR works monitoring behaviors of the running applications.&lt;/P&gt;
&lt;P&gt;You can create a "report only" profile and apply it to this kind of servers and then monitor if the agent detects something from this application as malicious, and then create the exceptions based on the XDR agent detections.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2024 14:07:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/adding-file-and-folder-exclusions/m-p/598422#M7205</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-09-20T14:07:49Z</dc:date>
    </item>
  </channel>
</rss>

