<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XDR Acting as Application Control for Linux in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-acting-as-application-control-for-linux/m-p/598267#M7200</link>
    <description>&lt;P data-unlink="true"&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1109520615"&gt;@rafael&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you for reaching out to the Live community!&lt;BR /&gt;&lt;BR /&gt;Basically, CortexXDR has features like &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Manage-file-execution" target="_self"&gt;Hash control ,&lt;/A&gt;&lt;SPAN&gt;Restriction policies (&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/File-Analysis-and-Protection-Flow" target="_blank"&gt;Phase2 &amp;amp; 3&lt;/A&gt; ) &amp;amp; &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/BIOC-Rule-Details" target="_blank"&gt;BIOCs&lt;/A&gt; etc,.. that can be used to manage files and applications effectively.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;But&lt;SPAN&gt;&amp;nbsp;generally speaking,&amp;nbsp;&lt;/SPAN&gt;transforming XDR solution into solely an application control solution may not be good idea since&amp;nbsp;&lt;SPAN&gt;App control is a legacy control solution that leaves companies open to supply chain attacks,&amp;nbsp;lolbins, and much more...&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;Please click&amp;nbsp;Accept as Solution&amp;nbsp;to acknowledge&amp;nbsp;If this answer added value to your question.&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Sep 2024 11:26:45 GMT</pubDate>
    <dc:creator>nar</dc:creator>
    <dc:date>2024-09-19T11:26:45Z</dc:date>
    <item>
      <title>XDR Acting as Application Control for Linux</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-acting-as-application-control-for-linux/m-p/598208#M7199</link>
      <description>&lt;P&gt;Hi Community,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've managed to transform &lt;STRONG&gt;Palo Alto Networks' Cortex XDR&lt;/STRONG&gt; into an effective &lt;STRONG&gt;application control&lt;/STRONG&gt; solution for Linux based on the hashes of the files.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Has anyone else tried this method previously?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 23:18:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-acting-as-application-control-for-linux/m-p/598208#M7199</guid>
      <dc:creator>rafael</dc:creator>
      <dc:date>2024-09-18T23:18:42Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Acting as Application Control for Linux</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-acting-as-application-control-for-linux/m-p/598267#M7200</link>
      <description>&lt;P data-unlink="true"&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1109520615"&gt;@rafael&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you for reaching out to the Live community!&lt;BR /&gt;&lt;BR /&gt;Basically, CortexXDR has features like &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Manage-file-execution" target="_self"&gt;Hash control ,&lt;/A&gt;&lt;SPAN&gt;Restriction policies (&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/File-Analysis-and-Protection-Flow" target="_blank"&gt;Phase2 &amp;amp; 3&lt;/A&gt; ) &amp;amp; &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/BIOC-Rule-Details" target="_blank"&gt;BIOCs&lt;/A&gt; etc,.. that can be used to manage files and applications effectively.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;But&lt;SPAN&gt;&amp;nbsp;generally speaking,&amp;nbsp;&lt;/SPAN&gt;transforming XDR solution into solely an application control solution may not be good idea since&amp;nbsp;&lt;SPAN&gt;App control is a legacy control solution that leaves companies open to supply chain attacks,&amp;nbsp;lolbins, and much more...&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;Please click&amp;nbsp;Accept as Solution&amp;nbsp;to acknowledge&amp;nbsp;If this answer added value to your question.&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 11:26:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-acting-as-application-control-for-linux/m-p/598267#M7200</guid>
      <dc:creator>nar</dc:creator>
      <dc:date>2024-09-19T11:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Acting as Application Control for Linux</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-acting-as-application-control-for-linux/m-p/598315#M7202</link>
      <description>&lt;P&gt;It is true that BIOC rules allow you to detect behaviour, this functionality of Application control with cortex restricts Linux Servers to use files that aren´t whitelisted by you. I dont agree since it could be a great use for restricted servers with important information.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 15:49:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-acting-as-application-control-for-linux/m-p/598315#M7202</guid>
      <dc:creator>rafael</dc:creator>
      <dc:date>2024-09-19T15:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Acting as Application Control for Linux</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-acting-as-application-control-for-linux/m-p/598356#M7203</link>
      <description>&lt;P&gt;Custom BIOC rules can be added to the restriction profile to restrict the file execution and to have more granular control than just detection, could be used as an application control over restricted servers or on servers that have tight hardening which are not exposed to outside infra easily but the point I was making is to effectively use XDR solution for the purpose it is built for than just using it as&amp;nbsp;&lt;SPAN&gt;legacy&lt;/SPAN&gt; &lt;SPAN&gt;App control solution.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 19:49:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-acting-as-application-control-for-linux/m-p/598356#M7203</guid>
      <dc:creator>nar</dc:creator>
      <dc:date>2024-09-19T19:49:00Z</dc:date>
    </item>
  </channel>
</rss>

