<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XDR Legacy Agent Exception's behavior in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-legacy-agent-exception-s-behavior/m-p/1241545#M8859</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P data-start="74" data-end="447"&gt;We have confirmed through the official manual that XDR does not perform evaluation on files or paths allowed under &lt;STRONG data-start="189" data-end="219"&gt;XDR Legacy Agent Exception&lt;/STRONG&gt;.&lt;BR data-start="220" data-end="223" /&gt;What I would like to know is whether files covered by a &lt;STRONG data-start="279" data-end="312"&gt;Legacy Agent Exception policy&lt;/STRONG&gt; also do &lt;STRONG data-start="321" data-end="344"&gt;not generate alerts&lt;/STRONG&gt;.&lt;BR data-start="345" data-end="348" /&gt;I would also like to confirm if this behavior is explicitly stated in the official documentation.&lt;/P&gt;
&lt;P data-start="449" data-end="755"&gt;Currently, we have observed that even after configuring &lt;STRONG data-start="505" data-end="525"&gt;Alert Exclusions&lt;/STRONG&gt;, alerts of the same type continue to appear.&lt;BR data-start="570" data-end="573" /&gt;While we could add additional Alert Exclusions, our goal is to use &lt;STRONG data-start="640" data-end="666"&gt;Legacy Agent Exception&lt;/STRONG&gt; for items that should be clearly allowed, in order to reduce unnecessary alert counts.&lt;/P&gt;
&lt;P data-start="757" data-end="773"&gt;&lt;STRONG data-start="757" data-end="771"&gt;Questions:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL data-start="774" data-end="911"&gt;
&lt;LI data-start="774" data-end="866"&gt;
&lt;P data-start="777" data-end="866"&gt;Do files/paths configured under a Legacy Agent Exception also prevent alert generation?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="867" data-end="911"&gt;
&lt;P data-start="870" data-end="911"&gt;Is this behavior officially documented?&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-start="913" data-end="923" data-is-last-node="" data-is-only-node=""&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Nov 2025 00:08:23 GMT</pubDate>
    <dc:creator>C.Seokgun</dc:creator>
    <dc:date>2025-11-11T00:08:23Z</dc:date>
    <item>
      <title>XDR Legacy Agent Exception's behavior</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-legacy-agent-exception-s-behavior/m-p/1241545#M8859</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P data-start="74" data-end="447"&gt;We have confirmed through the official manual that XDR does not perform evaluation on files or paths allowed under &lt;STRONG data-start="189" data-end="219"&gt;XDR Legacy Agent Exception&lt;/STRONG&gt;.&lt;BR data-start="220" data-end="223" /&gt;What I would like to know is whether files covered by a &lt;STRONG data-start="279" data-end="312"&gt;Legacy Agent Exception policy&lt;/STRONG&gt; also do &lt;STRONG data-start="321" data-end="344"&gt;not generate alerts&lt;/STRONG&gt;.&lt;BR data-start="345" data-end="348" /&gt;I would also like to confirm if this behavior is explicitly stated in the official documentation.&lt;/P&gt;
&lt;P data-start="449" data-end="755"&gt;Currently, we have observed that even after configuring &lt;STRONG data-start="505" data-end="525"&gt;Alert Exclusions&lt;/STRONG&gt;, alerts of the same type continue to appear.&lt;BR data-start="570" data-end="573" /&gt;While we could add additional Alert Exclusions, our goal is to use &lt;STRONG data-start="640" data-end="666"&gt;Legacy Agent Exception&lt;/STRONG&gt; for items that should be clearly allowed, in order to reduce unnecessary alert counts.&lt;/P&gt;
&lt;P data-start="757" data-end="773"&gt;&lt;STRONG data-start="757" data-end="771"&gt;Questions:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL data-start="774" data-end="911"&gt;
&lt;LI data-start="774" data-end="866"&gt;
&lt;P data-start="777" data-end="866"&gt;Do files/paths configured under a Legacy Agent Exception also prevent alert generation?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="867" data-end="911"&gt;
&lt;P data-start="870" data-end="911"&gt;Is this behavior officially documented?&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-start="913" data-end="923" data-is-last-node="" data-is-only-node=""&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2025 00:08:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-legacy-agent-exception-s-behavior/m-p/1241545#M8859</guid>
      <dc:creator>C.Seokgun</dc:creator>
      <dc:date>2025-11-11T00:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Legacy Agent Exception's behavior</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-legacy-agent-exception-s-behavior/m-p/1245081#M8971</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/373103033"&gt;@C.Seokgun&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greeting for the day.&lt;/P&gt;
&lt;P&gt;Whether a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Legacy Agent Exception&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;prevents alert generation depends on the specific protection module for which the exception is configured.&lt;/P&gt;
&lt;H3&gt;1. Do Legacy Agent Exceptions prevent alert generation?&lt;/H3&gt;
&lt;P&gt;The behavior varies by module:&lt;BR /&gt;*&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Malware Evaluation Modules (e.g., Portable Executable and DLL Examination, Endpoint Scanning):&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Configuring a Legacy Agent Exception for these modules generally instructs the agent to skip evaluation entirely. In these cases, the exception&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;does prevent&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;both the blocking action and the generation of an alert in the console.&lt;BR /&gt;*&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Behavioral Threat Protection (BTP) and Credential Gathering Protection (DSE):&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Adding a process or path to the Legacy Agent Exception list for these modules will stop the agent from terminating or blocking the process, but&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;it will not prevent alert generation&lt;/STRONG&gt;. Instead, the console will continue to display "Detected (Reported)" alerts to indicate that a potential threat was identified but permitted due to the exception. To fully suppress these alerts, you must create a specific&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Alert Exception&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(or Alert Exclusion).&lt;/P&gt;
&lt;H3&gt;2. Is this behavior officially documented?&lt;/H3&gt;
&lt;P&gt;Yes, this behavior is explicitly mentioned in official documentation and internal Knowledge Base articles for various modules:&lt;BR /&gt;* For the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Office Files with Macros Examination&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;module, the manual states: "Adding a process to the allow list doesn’t prevent the generation of a security event".&lt;BR /&gt;* General Malware Security Profile documentation notes: "Processes on the allow list will not be terminated by the agent when they are part of a malicious causality chain. Alerts will be triggered regardless".&lt;/P&gt;
&lt;H3&gt;Additional Recommendations&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Operational Agent Exception:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If your goal is to completely exclude a process or path from all monitoring and intervention (available for Windows agents 8.7+), you should use an&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Operational Agent Exception&lt;/STRONG&gt;. This broad exception disables major Endpoint Protection Modules (EPMs), anti-malware triggers, and most event collection for the specified item, effectively preventing alerts across the board.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Alert Exclusion Issues:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;You mentioned that alerts continue to appear even after configuring Alert Exclusions. This typically occurs if the exclusion criteria (such as the exact process path, command line, or signer) do not perfectly match the data in the generated alert. It is recommended to create the exclusion directly from the alert itself by right-clicking the alert and selecting&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Manage Alert &amp;gt; Create Alert Exception&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to ensure matching accuracy.&lt;/LI&gt;
&lt;/UL&gt;
&lt;SECTION class="title" lang="en-US" tabindex="-1" data-highlight-html-query="Alert exception"&gt;
&lt;DIV class="depth-6 content-locale-en-US "&gt;
&lt;SECTION class="title" lang="en-US" tabindex="-1" data-highlight-html-query="Alert exception"&gt;
&lt;DIV class="depth-6 content-locale-en-US "&gt;
&lt;H4&gt;&lt;MARK class="highlight-html-match" data-markjs="true"&gt;Exception&lt;/MARK&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;configuration:&lt;/H4&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Documentation/Exception-configuration" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Documentation/Exception-configuration&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008VeHCAU" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008VeHCAU&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Happy New Year!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2026 15:47:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-legacy-agent-exception-s-behavior/m-p/1245081#M8971</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-01-07T15:47:01Z</dc:date>
    </item>
  </channel>
</rss>

