<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Adding batch and Powershell scripts to XDR blocklist in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/adding-batch-and-powershell-scripts-to-xdr-blocklist/m-p/1225819#M8190</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Considering PE, PE64 and macro enabled Word and Excel documents are allowed to be entered to blocklist, does it make any sense to add a .bat or a powershell PS1 file to the XDR blocklist&amp;nbsp;&lt;/SPAN&gt;&lt;A id="hoverCardLink" class="lia-link-navigation lia-product-hover-card-link lia-product-mention lia-tooltip-trigger" href="https://live.paloaltonetworks.com/t5/c-twzvq79624/Cortex+XDR/pd-p/Cortex_XDR" aria-describedby="hoverCardLink_0-tooltip-element" aria-controls="hoverCardLink_0-tooltip-element" target="_blank"&gt;Cortex XDR&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Apr 2025 08:52:31 GMT</pubDate>
    <dc:creator>VarunPitale</dc:creator>
    <dc:date>2025-04-07T08:52:31Z</dc:date>
    <item>
      <title>Adding batch and Powershell scripts to XDR blocklist</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/adding-batch-and-powershell-scripts-to-xdr-blocklist/m-p/1225819#M8190</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Considering PE, PE64 and macro enabled Word and Excel documents are allowed to be entered to blocklist, does it make any sense to add a .bat or a powershell PS1 file to the XDR blocklist&amp;nbsp;&lt;/SPAN&gt;&lt;A id="hoverCardLink" class="lia-link-navigation lia-product-hover-card-link lia-product-mention lia-tooltip-trigger" href="https://live.paloaltonetworks.com/t5/c-twzvq79624/Cortex+XDR/pd-p/Cortex_XDR" aria-describedby="hoverCardLink_0-tooltip-element" aria-controls="hoverCardLink_0-tooltip-element" target="_blank"&gt;Cortex XDR&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 08:52:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/adding-batch-and-powershell-scripts-to-xdr-blocklist/m-p/1225819#M8190</guid>
      <dc:creator>VarunPitale</dc:creator>
      <dc:date>2025-04-07T08:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: Adding batch and Powershell scripts to XDR blocklist</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/adding-batch-and-powershell-scripts-to-xdr-blocklist/m-p/1225894#M8192</link>
      <description>&lt;P class="" data-start="52" data-end="441"&gt;Honestly, adding a&lt;STRONG data-start="62" data-end="126"&gt;&lt;CODE data-start="73" data-end="79"&gt;.bat&lt;/CODE&gt;&lt;/STRONG&gt;or &lt;STRONG data-start="62" data-end="126"&gt;&lt;CODE data-start="83" data-end="89"&gt;.ps1&lt;/CODE&gt;&amp;nbsp;&lt;/STRONG&gt;file to the XDR blocklist can work, but only in very specific cases. you are basically telling XDR, &lt;EM data-start="191" data-end="255"&gt;“&lt;/EM&gt;&lt;STRONG&gt;Hey, if you see this exact file (by its hash), block it.&lt;/STRONG&gt;&lt;EM data-start="191" data-end="255"&gt;”&lt;/EM&gt; That’s cool if you’re dealing with a known, unchanging script but let’s be real, attackers don’t usually play that way. scripts change, get obfuscated, renamed, or generated on the fly.&lt;/P&gt;
&lt;P class="" data-start="443" data-end="565"&gt;So, does it make sense? Yes.&amp;nbsp; but only if&amp;nbsp;you are targeting a very specific threat and you’ve got the exact hash.&lt;/P&gt;
&lt;P class="" data-start="567" data-end="616"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="567" data-end="616"&gt;But for broader protection? Not really ideal.&lt;/P&gt;
&lt;P class="" data-start="567" data-end="616"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="618" data-end="971"&gt;If your goal is to stop &lt;CODE data-start="642" data-end="648"&gt;.bat&lt;/CODE&gt; or PowerShell scripts from running altogether (especially in places they shouldn’t be), you’re better off using a Restrictions Security Profile. That lets you say, “Don’t allow any scripts from these folders,” or “Block scripts entirely.” It’s way more flexible and doesn’t rely on the file being identical every time.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 05:41:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/adding-batch-and-powershell-scripts-to-xdr-blocklist/m-p/1225894#M8192</guid>
      <dc:creator>Chamindu</dc:creator>
      <dc:date>2025-04-08T05:41:41Z</dc:date>
    </item>
  </channel>
</rss>

