<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Blocking connections to malicious IP address? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-connections-to-malicious-ip-address/m-p/617834#M7425</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a question. I have Cortex XDR agents installed on my endpoints. I just recently also installed Forti Analyzer and it detected some potential malicious IP addresses that my endpoints have connections to. I wonder why Cortex XDR cannot detect and block connections to these malicious IP addresses. Some of these malicious IPs are&amp;nbsp;139.45.197.252, 139.45.197.227,&amp;nbsp;139.45.197.151,&amp;nbsp;139.45.197.236.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: My all profiles are in block mode and nothing in allow/block list.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Nov 2024 20:23:48 GMT</pubDate>
    <dc:creator>JahidAliyev</dc:creator>
    <dc:date>2024-11-14T20:23:48Z</dc:date>
    <item>
      <title>Blocking connections to malicious IP address?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-connections-to-malicious-ip-address/m-p/617834#M7425</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a question. I have Cortex XDR agents installed on my endpoints. I just recently also installed Forti Analyzer and it detected some potential malicious IP addresses that my endpoints have connections to. I wonder why Cortex XDR cannot detect and block connections to these malicious IP addresses. Some of these malicious IPs are&amp;nbsp;139.45.197.252, 139.45.197.227,&amp;nbsp;139.45.197.151,&amp;nbsp;139.45.197.236.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: My all profiles are in block mode and nothing in allow/block list.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 20:23:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-connections-to-malicious-ip-address/m-p/617834#M7425</guid>
      <dc:creator>JahidAliyev</dc:creator>
      <dc:date>2024-11-14T20:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking connections to malicious IP address?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-connections-to-malicious-ip-address/m-p/620417#M7429</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/274228"&gt;@JahidAliyev&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for your query on LC!&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Basically,&amp;nbsp;Cortex XDR will not monitor the network Traffic, it will block if any malicious activity occurs on the endpoint with any process execution.&lt;BR /&gt;Cortex XDR agent identifies a remote network connection that attempts to perform malicious activity—such as encrypting endpoint files—the agent can automatically block the IP address to close all existing communication and block new connections from this IP address to the endpoint.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;So,&amp;nbsp;&lt;SPAN&gt;Cortex XDR agent does not block connection attempts to remote addresses if this connection does not yield further activity. If there is no malicious activity was initiated due to this connection. If the connection to that remote address would have executed any harmful activity, the XDR agent should have prevented it before causing any damage.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;Based on the above facts, I think its worth investigating this activity and the endpoint where traffic being initiated to see if any anomalies and also checking the firewall.&lt;BR /&gt;&lt;BR /&gt;Give it a like or mark this response as a solution if this added value to your question.&lt;BR /&gt;&lt;BR /&gt;Best,&lt;BR /&gt;Naveen&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2024 07:27:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-connections-to-malicious-ip-address/m-p/620417#M7429</guid>
      <dc:creator>nar</dc:creator>
      <dc:date>2024-11-16T07:27:09Z</dc:date>
    </item>
  </channel>
</rss>

