<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR False Positive Report in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-false-positive-report/m-p/728500#M7485</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;We develop some applications and our customer told us when they install the application, it gives a malicious warning for a sub installer "gcad_local.exe". Is it possible to submit the file to Cortex XDR and add it to whitelist in some way?&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 27 Nov 2024 08:14:21 GMT</pubDate>
    <dc:creator>york</dc:creator>
    <dc:date>2024-11-27T08:14:21Z</dc:date>
    <item>
      <title>Cortex XDR False Positive Report</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-false-positive-report/m-p/728500#M7485</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;We develop some applications and our customer told us when they install the application, it gives a malicious warning for a sub installer "gcad_local.exe". Is it possible to submit the file to Cortex XDR and add it to whitelist in some way?&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 08:14:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-false-positive-report/m-p/728500#M7485</guid>
      <dc:creator>york</dc:creator>
      <dc:date>2024-11-27T08:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR False Positive Report</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-false-positive-report/m-p/731162#M7489</link>
      <description>&lt;P&gt;Hello Sir, thanks for your reply! However, this applicaiton will also be used among other customers who also use Cortex XDR on their machine. I am afraid they will still meet same error and think there is a virus with our application. Is there a way to submit it to paloalto to scan the file, so that this application will not be blocked by any Cortex XDR users anymore?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 08:29:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-false-positive-report/m-p/731162#M7489</guid>
      <dc:creator>york</dc:creator>
      <dc:date>2024-11-27T08:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR False Positive Report</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-false-positive-report/m-p/995588#M7497</link>
      <description>&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;DIV class="p-rich_text_section"&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/574028009"&gt;@york&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;To answer this, we first need to understand what module is blocking it, Is it Wildfire or Local analysis or something else and based on that the exceptions work.If you are looking to analyze an .exe file then we have Wildfire engine from which CortexXDR Auto upload/analyze/compare and pull the verdicts from.&lt;BR /&gt;Ref -&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="c-link" href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/WildFire-analysis-concepts" target="_blank" rel="noopener noreferrer" data-stringify-link="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/WildFire-analysis-concepts" data-sk="tooltip_parent"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/WildFire-analysis-concepts&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;If you want to manually do this analysis on a file then this is the portal link -&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="c-link" href="https://docs.paloaltonetworks.com/advanced-wildfire/administration/configure-advanced-wildfire-analysis/manually-upload-files-to-the-wildfire-portal" target="_blank" rel="noopener noreferrer" data-stringify-link="https://docs.paloaltonetworks.com/advanced-wildfire/administration/configure-advanced-wildfire-analysis/manually-upload-files-to-the-wildfire-portal" data-sk="tooltip_parent"&gt;https://docs.paloaltonetworks.com/advanced-wildfire/administration/configure-advanced-wildfire-analysis/manually-upload-files-to-the-wildfire-portal&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Give it a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG data-stringify-type="bold"&gt;like&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;amp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG data-stringify-type="bold"&gt;mark&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;this as&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG data-stringify-type="bold"&gt;solution&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;if this answered your query.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="c-message_kit__attachments"&gt;
&lt;DIV class="c-message_attachment" data-qa="message_attachment_default"&gt;
&lt;DIV class="c-message_attachment__delete_container"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="c-message_attachment__border"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="c-message_attachment__body"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 28 Nov 2024 06:54:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-false-positive-report/m-p/995588#M7497</guid>
      <dc:creator>nar</dc:creator>
      <dc:date>2024-11-28T06:54:59Z</dc:date>
    </item>
  </channel>
</rss>

