<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic BTP Exception not working for ps1 script in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/btp-exception-not-working-for-ps1-script/m-p/1229979#M8334</link>
    <description>&lt;P&gt;Hi Team -&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I've created a Legacy Agent Exception Rule to prevent the Behavioral Threat Protection component from blocking a specific (and legitimate) .ps1 file on my network (within a specific user profile), but Cortex keeps blocking the script.&lt;/P&gt;
&lt;P&gt;The command line in the alert is:&lt;/P&gt;
&lt;P data-start="396" data-end="429"&gt;"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "-file" " C:\Temp\ScriptName.ps1 "&lt;BR /&gt;&lt;BR /&gt;The exclusion rule was created as follows:&lt;BR data-start="574" data-end="577" /&gt;Platform: Windows&lt;BR data-start="598" data-end="601" /&gt;Module: Behavioral Threat Protection&lt;/P&gt;
&lt;P data-start="645" data-end="741"&gt;Here are the options I've tried under Target Properties → Files / Folders in allow list:&lt;/P&gt;
&lt;UL data-start="742" data-end="856"&gt;
&lt;LI data-start="742" data-end="761"&gt;*ScriptName.ps1&lt;/LI&gt;
&lt;LI data-start="762" data-end="788"&gt;C:\Temp\ScriptName.ps1&lt;/LI&gt;
&lt;LI data-start="789" data-end="830"&gt;powershell.exe-fileScriptName.ps1&lt;/LI&gt;
&lt;LI data-start="831" data-end="856"&gt;-file *ScriptName.ps1&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="858" data-end="887"&gt;Prevention information:&lt;/P&gt;
&lt;UL data-start="888" data-end="1124"&gt;
&lt;LI data-start="888" data-end="918"&gt;OS version: 10.0.26100&lt;/LI&gt;
&lt;LI data-start="919" data-end="966"&gt;Component: Behavioral Threat Protection&lt;/LI&gt;
&lt;LI data-start="967" data-end="996"&gt;Status code: c0400067&lt;/LI&gt;
&lt;LI data-start="997" data-end="1055"&gt;Prevention description: Behavioral threat detected&lt;/LI&gt;
&lt;LI data-start="1056" data-end="1124"&gt;Additional information 1: Rule amsi_malicious.b.464633143106&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Sun, 25 May 2025 12:57:53 GMT</pubDate>
    <dc:creator>L.Shmarya</dc:creator>
    <dc:date>2025-05-25T12:57:53Z</dc:date>
    <item>
      <title>BTP Exception not working for ps1 script</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/btp-exception-not-working-for-ps1-script/m-p/1229979#M8334</link>
      <description>&lt;P&gt;Hi Team -&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I've created a Legacy Agent Exception Rule to prevent the Behavioral Threat Protection component from blocking a specific (and legitimate) .ps1 file on my network (within a specific user profile), but Cortex keeps blocking the script.&lt;/P&gt;
&lt;P&gt;The command line in the alert is:&lt;/P&gt;
&lt;P data-start="396" data-end="429"&gt;"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "-file" " C:\Temp\ScriptName.ps1 "&lt;BR /&gt;&lt;BR /&gt;The exclusion rule was created as follows:&lt;BR data-start="574" data-end="577" /&gt;Platform: Windows&lt;BR data-start="598" data-end="601" /&gt;Module: Behavioral Threat Protection&lt;/P&gt;
&lt;P data-start="645" data-end="741"&gt;Here are the options I've tried under Target Properties → Files / Folders in allow list:&lt;/P&gt;
&lt;UL data-start="742" data-end="856"&gt;
&lt;LI data-start="742" data-end="761"&gt;*ScriptName.ps1&lt;/LI&gt;
&lt;LI data-start="762" data-end="788"&gt;C:\Temp\ScriptName.ps1&lt;/LI&gt;
&lt;LI data-start="789" data-end="830"&gt;powershell.exe-fileScriptName.ps1&lt;/LI&gt;
&lt;LI data-start="831" data-end="856"&gt;-file *ScriptName.ps1&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="858" data-end="887"&gt;Prevention information:&lt;/P&gt;
&lt;UL data-start="888" data-end="1124"&gt;
&lt;LI data-start="888" data-end="918"&gt;OS version: 10.0.26100&lt;/LI&gt;
&lt;LI data-start="919" data-end="966"&gt;Component: Behavioral Threat Protection&lt;/LI&gt;
&lt;LI data-start="967" data-end="996"&gt;Status code: c0400067&lt;/LI&gt;
&lt;LI data-start="997" data-end="1055"&gt;Prevention description: Behavioral threat detected&lt;/LI&gt;
&lt;LI data-start="1056" data-end="1124"&gt;Additional information 1: Rule amsi_malicious.b.464633143106&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Sun, 25 May 2025 12:57:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/btp-exception-not-working-for-ps1-script/m-p/1229979#M8334</guid>
      <dc:creator>L.Shmarya</dc:creator>
      <dc:date>2025-05-25T12:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: BTP Exception not working for ps1 script</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/btp-exception-not-working-for-ps1-script/m-p/1230157#M8344</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/950972187"&gt;@L.Shmarya&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For BTP alerts related to powershell you need to reach out to Tech Support and get SUEX from them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking like and&amp;nbsp; on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2025 09:28:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/btp-exception-not-working-for-ps1-script/m-p/1230157#M8344</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2025-05-27T09:28:14Z</dc:date>
    </item>
  </channel>
</rss>

