<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR for Mac version 7.4.0 in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-for-mac-version-7-4-0/m-p/410376#M780</link>
    <description>&lt;P&gt;Hi, thanks for your reply. Actually Our support figured it out and did exactly that I suppose:&lt;/P&gt;&lt;P&gt;&amp;lt;snip&amp;gt;&lt;BR /&gt;&lt;SPAN&gt;Below has been added into allowed HASH list (as it were previously blocked by XDR&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/usr/local/share/dotnet/iTerm&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/usr/local/share/dotnet/dotnet&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/Library/Developer/PrivateFrameworks/CoreSimulator.framework/Versions/A/Resources/Platforms/iphoneos/usr/libexec/CoreSimulatorBridge&lt;BR /&gt;&lt;/SPAN&gt;&amp;lt;/snip&amp;gt;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Jun 2021 17:03:29 GMT</pubDate>
    <dc:creator>larsoleruben</dc:creator>
    <dc:date>2021-06-01T17:03:29Z</dc:date>
    <item>
      <title>Cortex XDR for Mac version 7.4.0</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-for-mac-version-7-4-0/m-p/410227#M778</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;I am using a MAC with BigSur version 11.4 and&amp;nbsp;Cortex XDR for Mac version 7.4.0&lt;BR /&gt;Suddenly I am no loger able to debug in Xcode, since the debug server i killed by Cortex.&lt;BR /&gt;Also when I debug from VSCode in C# I get a notification, but debugging does take place.&lt;BR /&gt;So basically my Mac is so safe that it is unusable. How can I get solve this?&lt;BR /&gt;&lt;BR /&gt;Error message:&lt;BR /&gt;Dylib-hijacking attempt detected&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Details&lt;BR /&gt;Prevention ID&lt;/STRONG&gt;&lt;/SPAN&gt;: fe1bb230-9eaf-4590-ab0b-507053bc0b8a&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Machine name&lt;/STRONG&gt;&lt;/SPAN&gt;: Taken away&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;OS Name&lt;/STRONG&gt;&lt;/SPAN&gt;: macOS&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;OS Version&lt;/STRONG&gt;&lt;/SPAN&gt;: OS X 11.4.0&lt;/P&gt;&lt;P class="p2"&gt;&lt;STRONG&gt;Cortex XDR version&lt;/STRONG&gt;&lt;SPAN class="s2"&gt;: 7.4.0.2226&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;STRONG&gt;Dump path&lt;/STRONG&gt;&lt;SPAN class="s2"&gt;: N/A&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;STRONG&gt;Content Version&lt;/STRONG&gt;&lt;SPAN class="s2"&gt;: 182-59165&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Mode&lt;/STRONG&gt;&lt;/SPAN&gt;: Terminate&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Module name&lt;/STRONG&gt;&lt;/SPAN&gt;: Dylib-Hijacking Protection&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Date&lt;/STRONG&gt;&lt;/SPAN&gt;: 31/05/2021, 23.57.34&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Verdict&lt;/STRONG&gt;&lt;/SPAN&gt;: Not Available&lt;/P&gt;&lt;P class="p2"&gt;&lt;STRONG&gt;Source Process ID&lt;/STRONG&gt;&lt;SPAN class="s2"&gt;: 2397&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;STRONG&gt;Source Process Command-Line&lt;/STRONG&gt;&lt;SPAN class="s2"&gt;: N/A&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Source User Name&lt;/STRONG&gt;&lt;/SPAN&gt;: larschristoffersen&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 22:01:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-for-mac-version-7-4-0/m-p/410227#M778</guid>
      <dc:creator>larsoleruben</dc:creator>
      <dc:date>2021-05-31T22:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR for Mac version 7.4.0</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-for-mac-version-7-4-0/m-p/410371#M779</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167659"&gt;@larsoleruben&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi&lt;BR /&gt;I am using a MAC with BigSur version 11.4 and&amp;nbsp;Cortex XDR for Mac version 7.4.0&lt;BR /&gt;Suddenly I am no loger able to debug in Xcode, since the debug server i killed by Cortex.&lt;BR /&gt;Also when I debug from VSCode in C# I get a notification, but debugging does take place.&lt;BR /&gt;So basically my Mac is so safe that it is unusable. How can I get solve this?&lt;BR /&gt;&lt;BR /&gt;Error message:&lt;BR /&gt;Dylib-hijacking attempt detected&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Details&lt;BR /&gt;Prevention ID&lt;/STRONG&gt;&lt;/SPAN&gt;: fe1bb230-9eaf-4590-ab0b-507053bc0b8a&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Machine name&lt;/STRONG&gt;&lt;/SPAN&gt;: Taken away&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;OS Name&lt;/STRONG&gt;&lt;/SPAN&gt;: macOS&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;OS Version&lt;/STRONG&gt;&lt;/SPAN&gt;: OS X 11.4.0&lt;/P&gt;&lt;P class="p2"&gt;&lt;STRONG&gt;Cortex XDR version&lt;/STRONG&gt;&lt;SPAN class="s2"&gt;: 7.4.0.2226&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;STRONG&gt;Dump path&lt;/STRONG&gt;&lt;SPAN class="s2"&gt;: N/A&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;STRONG&gt;Content Version&lt;/STRONG&gt;&lt;SPAN class="s2"&gt;: 182-59165&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Mode&lt;/STRONG&gt;&lt;/SPAN&gt;: Terminate&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Module name&lt;/STRONG&gt;&lt;/SPAN&gt;: Dylib-Hijacking Protection&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Date&lt;/STRONG&gt;&lt;/SPAN&gt;: 31/05/2021, 23.57.34&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Verdict&lt;/STRONG&gt;&lt;/SPAN&gt;: Not Available&lt;/P&gt;&lt;P class="p2"&gt;&lt;STRONG&gt;Source Process ID&lt;/STRONG&gt;&lt;SPAN class="s2"&gt;: 2397&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;STRONG&gt;Source Process Command-Line&lt;/STRONG&gt;&lt;SPAN class="s2"&gt;: N/A&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Source User Name&lt;/STRONG&gt;&lt;/SPAN&gt;: larschristoffersen&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167659"&gt;@larsoleruben&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I understand that the Dylib Hijacking Protection module is preventing you from executing sanctioned software. Have you had the opportunity to create exceptions for the process in the restrictions profile for your endpoint? It would look similar to the following images. If so, what were your results?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gjenkins_1-1622564794099.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34163i9D09745C41E57824/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="gjenkins_1-1622564794099.png" alt="gjenkins_1-1622564794099.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gjenkins_0-1622564784624.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34162i2FCB9C2A12D0E31E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="gjenkins_0-1622564784624.png" alt="gjenkins_0-1622564784624.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 16:27:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-for-mac-version-7-4-0/m-p/410371#M779</guid>
      <dc:creator>gjenkins</dc:creator>
      <dc:date>2021-06-01T16:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR for Mac version 7.4.0</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-for-mac-version-7-4-0/m-p/410376#M780</link>
      <description>&lt;P&gt;Hi, thanks for your reply. Actually Our support figured it out and did exactly that I suppose:&lt;/P&gt;&lt;P&gt;&amp;lt;snip&amp;gt;&lt;BR /&gt;&lt;SPAN&gt;Below has been added into allowed HASH list (as it were previously blocked by XDR&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/usr/local/share/dotnet/iTerm&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/usr/local/share/dotnet/dotnet&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/Library/Developer/PrivateFrameworks/CoreSimulator.framework/Versions/A/Resources/Platforms/iphoneos/usr/libexec/CoreSimulatorBridge&lt;BR /&gt;&lt;/SPAN&gt;&amp;lt;/snip&amp;gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 17:03:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-for-mac-version-7-4-0/m-p/410376#M780</guid>
      <dc:creator>larsoleruben</dc:creator>
      <dc:date>2021-06-01T17:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR for Mac version 7.4.0</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-for-mac-version-7-4-0/m-p/410379#M781</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167659"&gt;@larsoleruben&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi&lt;BR /&gt;I am using a MAC with BigSur version 11.4 and&amp;nbsp;Cortex XDR for Mac version 7.4.0&lt;BR /&gt;Suddenly I am no loger able to debug in Xcode, since the debug server i killed by Cortex.&lt;BR /&gt;Also when I debug from VSCode in C# I get a notification, but debugging does take place.&lt;BR /&gt;So basically my Mac is so safe that it is unusable. How can I get solve this?&lt;BR /&gt;&lt;BR /&gt;Error message:&lt;BR /&gt;Dylib-hijacking attempt detected&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Details&lt;BR /&gt;Prevention ID&lt;/STRONG&gt;&lt;/SPAN&gt;: fe1bb230-9eaf-4590-ab0b-507053bc0b8a&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Machine name&lt;/STRONG&gt;&lt;/SPAN&gt;: Taken away&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;OS Name&lt;/STRONG&gt;&lt;/SPAN&gt;: macOS&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;OS Version&lt;/STRONG&gt;&lt;/SPAN&gt;: OS X 11.4.0&lt;/P&gt;&lt;P class="p2"&gt;&lt;STRONG&gt;Cortex XDR version&lt;/STRONG&gt;&lt;SPAN class="s2"&gt;: 7.4.0.2226&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;STRONG&gt;Dump path&lt;/STRONG&gt;&lt;SPAN class="s2"&gt;: N/A&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;STRONG&gt;Content Version&lt;/STRONG&gt;&lt;SPAN class="s2"&gt;: 182-59165&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Mode&lt;/STRONG&gt;&lt;/SPAN&gt;: Terminate&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Module name&lt;/STRONG&gt;&lt;/SPAN&gt;: Dylib-Hijacking Protection&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Date&lt;/STRONG&gt;&lt;/SPAN&gt;: 31/05/2021, 23.57.34&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Verdict&lt;/STRONG&gt;&lt;/SPAN&gt;: Not Available&lt;/P&gt;&lt;P class="p2"&gt;&lt;STRONG&gt;Source Process ID&lt;/STRONG&gt;&lt;SPAN class="s2"&gt;: 2397&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;STRONG&gt;Source Process Command-Line&lt;/STRONG&gt;&lt;SPAN class="s2"&gt;: N/A&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Source User Name&lt;/STRONG&gt;&lt;/SPAN&gt;: larschristoffersen&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167659"&gt;@larsoleruben&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Those images are of an Exceptions Security Profile - you can &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/exceptions-security-profiles/add-exceptions-profile.html#ida8c6e5c8-a702-436f-9ddf-ef16cbe96a6d" target="_self"&gt;create a security profile using the instructions found here&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Alternatively, you can add the exceptions globally &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/exceptions-security-profiles/add-a-global-endpoint-policy-exception.html#add-a-global-endpoint-policy-exception" target="_self"&gt;by following these instructions.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To see a video regarding exception creation and management, &lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-walkthroughs/exceptions-in-tms-and-cortex-xdr/ta-p/306384" target="_self"&gt;please see this video&lt;/A&gt; and skip to 2:42 for an in-depth walkthrough.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 17:08:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-for-mac-version-7-4-0/m-p/410379#M781</guid>
      <dc:creator>gjenkins</dc:creator>
      <dc:date>2021-06-01T17:08:24Z</dc:date>
    </item>
  </channel>
</rss>

