<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Quarantined File Automatically Moved to Allow List from Block List after File Restore Action in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantined-file-automatically-moved-to-allow-list-from-block/m-p/1236815#M8701</link>
    <description>&lt;P&gt;Have an interesting behavior that I was curious if anyone could clarify or validate. We recently enabled quarantine through malware profile/policy for&amp;nbsp;&lt;SPAN&gt;VB Scripts Examination a feature just recently added to Cortex XDR v8.9. As such a hash that was previously added to block list quarantined a .vbs file by sha256 and an end-user contacted us reporting the behavior (file missing) and validated the script as known and benign. While remediating the issue a SOC analyst restored the file by sha256 and it appears in management audit log that at the same time the file restore occurred, an action also occurred to move the hash from block list to allow list. The SOC Analyst confirmed that they had not yet moved the sha256 to allow list from block list so what appears to have occurred is at the time of the file restore the sha256 was also added to allow list. Furthermore, the action center showed action for "restore quarantine" but no action for "add to allow list" only the management audit log has this activity.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I reviewed the Palo Alto Documentation Portal and could not locate mention of this behavior:&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-4.x-Documentation/Manage-quarantined-files" target="_blank"&gt;Manage quarantined files • Cortex XDR 4.x Documentation • Palo Alto Networks documentation portal&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Mgmt Audit Log {Redacted}:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;20331886  Aug 27th 2025 19:04:20  soc.analyst@corp.com  SOC Analyst  Response  Create    Success  Low    Restore quarantined file with hash {HASH} on {HOST} and 13 other endpoints {IP}&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;20331885  Aug 27th 2025 19:04:20  soc.analyst@corp.com  SOC&amp;nbsp;&amp;nbsp;Analyst  Response  Enable    Success  Low    Enable and move 1 hash(es) from block list to allow list  {IP}  &lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 27 Aug 2025 20:04:33 GMT</pubDate>
    <dc:creator>Austin_Arzon</dc:creator>
    <dc:date>2025-08-27T20:04:33Z</dc:date>
    <item>
      <title>Quarantined File Automatically Moved to Allow List from Block List after File Restore Action</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantined-file-automatically-moved-to-allow-list-from-block/m-p/1236815#M8701</link>
      <description>&lt;P&gt;Have an interesting behavior that I was curious if anyone could clarify or validate. We recently enabled quarantine through malware profile/policy for&amp;nbsp;&lt;SPAN&gt;VB Scripts Examination a feature just recently added to Cortex XDR v8.9. As such a hash that was previously added to block list quarantined a .vbs file by sha256 and an end-user contacted us reporting the behavior (file missing) and validated the script as known and benign. While remediating the issue a SOC analyst restored the file by sha256 and it appears in management audit log that at the same time the file restore occurred, an action also occurred to move the hash from block list to allow list. The SOC Analyst confirmed that they had not yet moved the sha256 to allow list from block list so what appears to have occurred is at the time of the file restore the sha256 was also added to allow list. Furthermore, the action center showed action for "restore quarantine" but no action for "add to allow list" only the management audit log has this activity.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I reviewed the Palo Alto Documentation Portal and could not locate mention of this behavior:&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-4.x-Documentation/Manage-quarantined-files" target="_blank"&gt;Manage quarantined files • Cortex XDR 4.x Documentation • Palo Alto Networks documentation portal&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Mgmt Audit Log {Redacted}:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;20331886  Aug 27th 2025 19:04:20  soc.analyst@corp.com  SOC Analyst  Response  Create    Success  Low    Restore quarantined file with hash {HASH} on {HOST} and 13 other endpoints {IP}&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;20331885  Aug 27th 2025 19:04:20  soc.analyst@corp.com  SOC&amp;nbsp;&amp;nbsp;Analyst  Response  Enable    Success  Low    Enable and move 1 hash(es) from block list to allow list  {IP}  &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 20:04:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantined-file-automatically-moved-to-allow-list-from-block/m-p/1236815#M8701</guid>
      <dc:creator>Austin_Arzon</dc:creator>
      <dc:date>2025-08-27T20:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: Quarantined File Automatically Moved to Allow List from Block List after File Restore Action</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantined-file-automatically-moved-to-allow-list-from-block/m-p/1236835#M8702</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/278968"&gt;@Austin_Arzon&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's probably an expected behaviour. When clicking "restore file" you'll get asked if you want to add the hash to the allow list.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="micomi_0-1756357986017.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69036iD4B8FEB76C0EFA9E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="micomi_0-1756357986017.png" alt="micomi_0-1756357986017.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Aug 2025 05:13:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quarantined-file-automatically-moved-to-allow-list-from-block/m-p/1236835#M8702</guid>
      <dc:creator>micomi</dc:creator>
      <dc:date>2025-08-28T05:13:49Z</dc:date>
    </item>
  </channel>
</rss>

