<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exception to prevent the blocking of the Powershell/CMD command in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exception-to-prevent-the-blocking-of-the-powershell-cmd-command/m-p/1066188#M7712</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/891267549"&gt;@Aristooo&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can try by creating a Disable Prevention Rule under Configuration - Exceptions Configuration.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1736793263095.png" style="width: 753px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65174i795EAE6FB723FA22/image-dimensions/753x761?v=v2" width="753" height="761" role="button" title="jmazzeo_0-1736793263095.png" alt="jmazzeo_0-1736793263095.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can there enter the command that you need to create the exception, in the "Command line" field. Select the right module by choosing the one that is blocking the process in your case, I have selected BTP for the example which is the common one.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jan 2025 18:37:40 GMT</pubDate>
    <dc:creator>jmazzeo</dc:creator>
    <dc:date>2025-01-13T18:37:40Z</dc:date>
    <item>
      <title>Exception to prevent the blocking of the Powershell/CMD command</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exception-to-prevent-the-blocking-of-the-powershell-cmd-command/m-p/1000143#M7664</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi. How can I create an exception to prevent specific PowerShell and CMD commands from being blocked by XDR? &lt;BR /&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 06:39:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exception-to-prevent-the-blocking-of-the-powershell-cmd-command/m-p/1000143#M7664</guid>
      <dc:creator>Aristooo</dc:creator>
      <dc:date>2025-01-06T06:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Exception to prevent the blocking of the Powershell/CMD command</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exception-to-prevent-the-blocking-of-the-powershell-cmd-command/m-p/1066188#M7712</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/891267549"&gt;@Aristooo&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can try by creating a Disable Prevention Rule under Configuration - Exceptions Configuration.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1736793263095.png" style="width: 753px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65174i795EAE6FB723FA22/image-dimensions/753x761?v=v2" width="753" height="761" role="button" title="jmazzeo_0-1736793263095.png" alt="jmazzeo_0-1736793263095.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can there enter the command that you need to create the exception, in the "Command line" field. Select the right module by choosing the one that is blocking the process in your case, I have selected BTP for the example which is the common one.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 18:37:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exception-to-prevent-the-blocking-of-the-powershell-cmd-command/m-p/1066188#M7712</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2025-01-13T18:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: Exception to prevent the blocking of the Powershell/CMD command</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exception-to-prevent-the-blocking-of-the-powershell-cmd-command/m-p/1066543#M7717</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428"&gt;@jmazzeo&lt;/a&gt;&amp;nbsp;,&amp;nbsp; thanks for your response!&lt;BR /&gt;&lt;BR /&gt;In the CMD Line under Target Properties, can I replace some arguments with &lt;CODE&gt;*&lt;/CODE&gt;? For example, to capture all arguments in that part of the command. Like replacing &lt;CODE&gt;"curl &lt;A href="https://paloaltonetworks.com" target="_blank"&gt;https://paloaltonetworks.com&lt;/A&gt; --show-error"&lt;/CODE&gt; with &lt;CODE&gt;"curl https://* --show-error"&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 13:45:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exception-to-prevent-the-blocking-of-the-powershell-cmd-command/m-p/1066543#M7717</guid>
      <dc:creator>Aristooo</dc:creator>
      <dc:date>2025-01-14T13:45:51Z</dc:date>
    </item>
    <item>
      <title>Re: Exception to prevent the blocking of the Powershell/CMD command</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exception-to-prevent-the-blocking-of-the-powershell-cmd-command/m-p/1066550#M7718</link>
      <description>&lt;P&gt;Yes, you can use the asterisk as a wildcard.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 13:49:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exception-to-prevent-the-blocking-of-the-powershell-cmd-command/m-p/1066550#M7718</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2025-01-14T13:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: Exception to prevent the blocking of the Powershell/CMD command</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exception-to-prevent-the-blocking-of-the-powershell-cmd-command/m-p/1066556#M7719</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428"&gt;@jmazzeo&lt;/a&gt;&amp;nbsp;thank you very much!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 13:58:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exception-to-prevent-the-blocking-of-the-powershell-cmd-command/m-p/1066556#M7719</guid>
      <dc:creator>Aristooo</dc:creator>
      <dc:date>2025-01-14T13:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: Exception to prevent the blocking of the Powershell/CMD command</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exception-to-prevent-the-blocking-of-the-powershell-cmd-command/m-p/1223860#M8055</link>
      <description>&lt;P data-start="136" data-end="160"&gt;Hi Cortex XDR Community,&lt;/P&gt;
&lt;P data-start="162" data-end="378"&gt;I want to set up an alert in Cortex XDR that triggers whenever any user runs a PowerShell script. The alert should activate for any script or command executed in PowerShell, regardless of the user or specific script.&lt;/P&gt;
&lt;P data-start="380" data-end="511"&gt;Is there an existing rule or method to create such an alert for PowerShell usage? Any suggestions or examples would be appreciated.&lt;/P&gt;
&lt;P data-start="513" data-end="531"&gt;Thanks in advance!&lt;/P&gt;
&lt;P data-start="513" data-end="531"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 08:56:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exception-to-prevent-the-blocking-of-the-powershell-cmd-command/m-p/1223860#M8055</guid>
      <dc:creator>TurkanAsadova</dc:creator>
      <dc:date>2025-03-14T08:56:26Z</dc:date>
    </item>
  </channel>
</rss>

