<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic how remove softwares with XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-remove-softwares-with-xdr/m-p/997012#M7552</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I've two questions.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;First, I would like to know about your experience. How do you handle uninstalling software on specific devices that are not allowed and need to be removed via&amp;nbsp;&lt;/SPAN&gt;&lt;A id="hoverCardLink" class="lia-link-navigation lia-product-hover-card-link lia-product-mention lia-tooltip-trigger" href="https://live.paloaltonetworks.com/t5/c-twzvq79624/Cortex+XDR/pd-p/Cortex_XDR" target="_blank"&gt;Cortex XDR&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;without the user noticing?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The second question is: Is it possible to block apps? For example, I don’t want users to install Wireshark. Can it be blocked&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Dec 2024 18:46:50 GMT</pubDate>
    <dc:creator>tlmarques</dc:creator>
    <dc:date>2024-12-06T18:46:50Z</dc:date>
    <item>
      <title>how remove softwares with XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-remove-softwares-with-xdr/m-p/997012#M7552</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I've two questions.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;First, I would like to know about your experience. How do you handle uninstalling software on specific devices that are not allowed and need to be removed via&amp;nbsp;&lt;/SPAN&gt;&lt;A id="hoverCardLink" class="lia-link-navigation lia-product-hover-card-link lia-product-mention lia-tooltip-trigger" href="https://live.paloaltonetworks.com/t5/c-twzvq79624/Cortex+XDR/pd-p/Cortex_XDR" target="_blank"&gt;Cortex XDR&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;without the user noticing?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The second question is: Is it possible to block apps? For example, I don’t want users to install Wireshark. Can it be blocked&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 18:46:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-remove-softwares-with-xdr/m-p/997012#M7552</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-12-06T18:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: how remove softwares with XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-remove-softwares-with-xdr/m-p/997023#M7553</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both use cases are not supported as an OOTB feature, as the XDR solutions aims to prevent malware and alert on suspicious behavior in processes (and many etcetera).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyway, it can be achieved with workarounds like &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Run-scripts-on-an-endpoint" target="_self"&gt;running custom scripts&lt;/A&gt; for the first case, and creating &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Create-a-BIOC-rule" target="_self"&gt;custom BIOC rules&lt;/A&gt; to block the Wireshark executable by signer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 19:50:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-remove-softwares-with-xdr/m-p/997023#M7553</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-12-06T19:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: how remove softwares with XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-remove-softwares-with-xdr/m-p/997244#M7558</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428"&gt;@jmazzeo&lt;/a&gt;&amp;nbsp; thnks for your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my company, we have issues with some users installing prohibited applications (e.g., Chrome, Wireshark). I want to either remove these apps or create a policy to block them every time they are launched.&lt;/P&gt;
&lt;P&gt;Is it possible to create a BIOC rule and apply it to specific groups? Or would it be better to use an XQL query to exclude endpoints by name using the initiator field?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 14:30:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-remove-softwares-with-xdr/m-p/997244#M7558</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-12-09T14:30:00Z</dc:date>
    </item>
    <item>
      <title>Re: how remove softwares with XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-remove-softwares-with-xdr/m-p/997254#M7560</link>
      <description>&lt;P&gt;i've solved the exexcution with this:&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000XgyMCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000XgyMCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 15:40:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-remove-softwares-with-xdr/m-p/997254#M7560</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-12-09T15:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: how remove softwares with XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-remove-softwares-with-xdr/m-p/997255#M7561</link>
      <description>&lt;P&gt;That's great, that is the approach I mentioned in my previous post, using BIOC rules.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can apply the Restriction Profiles with the BIOC rules assigned to block to any different &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Define-Endpoint-Groups" target="_self"&gt;Endpoint Groups&lt;/A&gt; that you can configure from the console, or you can use your directory OUs or Groups (if applies) using the &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Set-Up-Cloud-Identity-Engine" target="_self"&gt;CIE integration&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 15:46:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-remove-softwares-with-xdr/m-p/997255#M7561</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-12-09T15:46:19Z</dc:date>
    </item>
  </channel>
</rss>

