<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR Ransomware Protection: Aggressive mode &amp;amp; Resource Optimization in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-ransomware-protection-aggressive-mode-amp-resource/m-p/999402#M7624</link>
    <description>&lt;P&gt;Hello Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a question regarding Cortex XDR in Aggressive Mode. During my testing, I noticed that it significantly impacts my machine's performance, as the Cortex XDR agent continuously analyzes the behavior of benign software, such as browsers.&lt;/P&gt;
&lt;P&gt;To optimize resource usage and performance, is it possible for Cortex XDR to analyze the behavior of benign software over an extended period (e.g., a month), establish a baseline, and then minimize or stop analyzing that software unless a deviation occurs?&lt;/P&gt;
&lt;P&gt;Does Cortex XDR offer a policy or configuration to support this kind of adaptive analysis, or are there other recommendations to mitigate resource usage in Aggressive Mode?&lt;/P&gt;
&lt;P&gt;Thank you for your insights!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;#contex_xdr&lt;/P&gt;
&lt;P&gt;#aggressive_mode&lt;/P&gt;</description>
    <pubDate>Tue, 24 Dec 2024 07:40:42 GMT</pubDate>
    <dc:creator>H.Zaw245320</dc:creator>
    <dc:date>2024-12-24T07:40:42Z</dc:date>
    <item>
      <title>Cortex XDR Ransomware Protection: Aggressive mode &amp; Resource Optimization</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-ransomware-protection-aggressive-mode-amp-resource/m-p/999402#M7624</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a question regarding Cortex XDR in Aggressive Mode. During my testing, I noticed that it significantly impacts my machine's performance, as the Cortex XDR agent continuously analyzes the behavior of benign software, such as browsers.&lt;/P&gt;
&lt;P&gt;To optimize resource usage and performance, is it possible for Cortex XDR to analyze the behavior of benign software over an extended period (e.g., a month), establish a baseline, and then minimize or stop analyzing that software unless a deviation occurs?&lt;/P&gt;
&lt;P&gt;Does Cortex XDR offer a policy or configuration to support this kind of adaptive analysis, or are there other recommendations to mitigate resource usage in Aggressive Mode?&lt;/P&gt;
&lt;P&gt;Thank you for your insights!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;#contex_xdr&lt;/P&gt;
&lt;P&gt;#aggressive_mode&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2024 07:40:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-ransomware-protection-aggressive-mode-amp-resource/m-p/999402#M7624</guid>
      <dc:creator>H.Zaw245320</dc:creator>
      <dc:date>2024-12-24T07:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Ransomware Protection: Aggressive mode &amp; Resource Optimization</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-ransomware-protection-aggressive-mode-amp-resource/m-p/999966#M7645</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56476653"&gt;@H.Zaw245320&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks for your query on LC!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Generally,&amp;nbsp;&amp;nbsp;we are not recommending to keep Aggressive Mode enabled always to avoid of this type of scenarios and also aggressive mode may make the decoy files distribute to many directries aggressively and be visible to users as well which may cause tampering attempts as well.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;Aggressive mode is part of ransomeware detection and this feature is designed for a scenarios where if user suspects that there is an infection they can enable it in such a scenario but should be disabled after.incase of customer is thinking that there is an infection they can enable it but should be disabled after.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="GV7HMNV2B-1735809404.252849-thread-list-Thread_1735813802.304769" class="c-virtual_list__item" tabindex="0" role="listitem" aria-setsize="-1" data-qa="virtual-list-item" data-item-key="1735813802.304769"&gt;
&lt;DIV class="c-message_kit__background c-message_kit__message c-message_kit__thread_message" role="presentation" data-qa="message_container" data-qa-unprocessed="false" data-qa-placeholder="false"&gt;
&lt;DIV class="c-message_kit__hover" role="document" aria-roledescription="message" data-qa-hover="true"&gt;
&lt;DIV class="c-message_kit__actions c-message_kit__actions--above"&gt;
&lt;DIV class="c-message_kit__gutter"&gt;
&lt;DIV class="c-message_kit__gutter__right" role="presentation" data-qa="message_content"&gt;
&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;DIV class="p-rich_text_section"&gt;Q- is it possible for Cortex XDR to analyze the behavior of benign software over an extended period (e.g., a month), establish a baseline, and then minimize or stop analyzing that software unless a deviation occurs?&lt;BR /&gt;A -&amp;nbsp; This may not be possible. The request is similar to our analytic engine over backend server but XDR Agent does not do this kind of processing on the agent bcz it requires so much data and time and processing power. Thats why we have analytics.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="GV7HMNV2B-1735809404.252849-thread-list-Thread_1735813870.886019" class="c-virtual_list__item" tabindex="-1" role="listitem" aria-setsize="-1" data-qa="virtual-list-item" data-item-key="1735813870.886019"&gt;
&lt;DIV class="c-message_kit__background c-message_kit__background--hovered c-message_kit__message c-message_kit__thread_message" role="presentation" data-qa="message_container" data-qa-unprocessed="false" data-qa-placeholder="false"&gt;
&lt;DIV class="c-message_kit__hover c-message_kit__hover--hovered" role="document" aria-roledescription="message" data-qa-hover="true"&gt;
&lt;DIV class="c-message_kit__actions c-message_kit__actions--above"&gt;
&lt;DIV class="c-message_kit__gutter"&gt;
&lt;DIV class="c-message_kit__gutter__left" role="presentation"&gt;
&lt;DIV class="p-thread_compact_gutter_generic p-thread_compact_gutter_generic--adjacent" data-qa="thread_compact_gutter"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="c-message_kit__gutter__right" role="presentation" data-qa="message_content"&gt;
&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;DIV class="p-rich_text_section"&gt;Q - Does Cortex XDR offer a policy or configuration to support this kind of adaptive analysis, or are there other recommendations to mitigate resource usage in Aggressive Mode?&lt;BR /&gt;A - We have Adaptive Policy (APEX) and Apex checks rules, modules etc built in with agent that monitors the overall resource consumptions in general but not specific/relevant to this feature. The option would be to&amp;nbsp;disable aggressive mode and not to keep enabled in general as explained above.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Give it a like and mark as solution if this helped.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;Best,&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2025 10:58:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-ransomware-protection-aggressive-mode-amp-resource/m-p/999966#M7645</guid>
      <dc:creator>nar</dc:creator>
      <dc:date>2025-01-02T10:58:59Z</dc:date>
    </item>
  </channel>
</rss>

