<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: linux agent change or remove without password - bug ?? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/linux-agent-change-or-remove-without-password-bug/m-p/1244973#M8953</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;The reason you can stop services or uninstall the Cortex XDR agent on Linux machines without a password is that the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;uninstall password and tamper protection features are not currently supported for the Linux platform.&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;These features are currently implemented only for Windows and macOS operating systems.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;As correctly said by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/323731019"&gt;@ssingh32&lt;/a&gt;&amp;nbsp;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additionally, sharing a few details:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="138" data-end="188"&gt;&lt;STRONG data-start="138" data-end="188"&gt;Key details regarding this limitation include:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="190" data-end="960"&gt;
&lt;LI data-start="190" data-end="573"&gt;
&lt;P data-start="192" data-end="573"&gt;&lt;STRONG data-start="192" data-end="215"&gt;OS-Specific Design:&lt;/STRONG&gt; On Linux, the Cortex XDR agent relies on the operating system's inherent security controls. Since uninstallation and service management (such as &lt;CODE data-start="361" data-end="382"&gt;cytool runtime stop&lt;/CODE&gt;) require superuser (root or sudo) privileges, the agent is designed to allow these actions once those elevated permissions are met, without prompting for an additional XDR-specific password.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="574" data-end="778"&gt;
&lt;P data-start="576" data-end="778"&gt;&lt;STRONG data-start="576" data-end="600"&gt;Profile Limitations:&lt;/STRONG&gt; The &lt;EM data-start="605" data-end="621"&gt;Agent Security&lt;/EM&gt; section, which contains the tamper protection and uninstall password settings in the management console, is not available for Linux Agent Settings profiles.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="779" data-end="960"&gt;
&lt;P data-start="781" data-end="960"&gt;&lt;STRONG data-start="781" data-end="801"&gt;Feature Request:&lt;/STRONG&gt; This is a known product limitation and is currently tracked under feature request &lt;STRONG data-start="884" data-end="898"&gt;CXDR-I-267&lt;/STRONG&gt; (Linux XDR agent security settings for tampering protection).&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="962" data-end="990"&gt;&lt;STRONG data-start="962" data-end="990"&gt;Recommended Workarounds:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL data-start="992" data-end="1523"&gt;
&lt;LI data-start="992" data-end="1112"&gt;
&lt;P data-start="995" data-end="1112"&gt;&lt;STRONG data-start="995" data-end="1030"&gt;Restrict Administrative Access:&lt;/STRONG&gt; Ensure that root or sudo access is limited strictly to authorized personnel only.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1113" data-end="1322"&gt;
&lt;P data-start="1116" data-end="1322"&gt;&lt;STRONG data-start="1116" data-end="1142"&gt;Monitoring and Alerts:&lt;/STRONG&gt; Configure notification forwarding or Audit Log filters in the Cortex XDR console to alert administrators when the agent service is stopped (TYPE = AGENT SERVICE, SUB-TYPE = STOP).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1323" data-end="1523"&gt;
&lt;P data-start="1326" data-end="1523"&gt;&lt;STRONG data-start="1326" data-end="1347"&gt;External Logging:&lt;/STRONG&gt; Use local utilities such as &lt;CODE data-start="1376" data-end="1385"&gt;rsyslog&lt;/CODE&gt; to forward logs from &lt;CODE data-start="1407" data-end="1424"&gt;/var/log/traps/&lt;/CODE&gt; to an external log management system to ensure audit trails are preserved if the agent is removed.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;"mark this as a Solution".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Happy New Year!!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Jan 2026 15:14:29 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-01-06T15:14:29Z</dc:date>
    <item>
      <title>linux agent change or remove without password - bug ??</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/linux-agent-change-or-remove-without-password-bug/m-p/1244756#M8940</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i've uninstall password setup for all devices on tenant, but on linux machines, it's possible stop services or uninstall agent without password.&lt;BR /&gt;&lt;BR /&gt;anyone knows why??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2025 17:36:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/linux-agent-change-or-remove-without-password-bug/m-p/1244756#M8940</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2025-12-30T17:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: linux agent change or remove without password - bug ??</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/linux-agent-change-or-remove-without-password-bug/m-p/1244959#M8950</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Linux is not having anti-tampering protection as a result&amp;nbsp;&lt;SPAN&gt;uninstall password is not available for linux endpoints.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;Please mark the solution as accepted ,if it helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jan 2026 12:05:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/linux-agent-change-or-remove-without-password-bug/m-p/1244959#M8950</guid>
      <dc:creator>ssingh32</dc:creator>
      <dc:date>2026-01-06T12:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: linux agent change or remove without password - bug ??</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/linux-agent-change-or-remove-without-password-bug/m-p/1244973#M8953</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;The reason you can stop services or uninstall the Cortex XDR agent on Linux machines without a password is that the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;uninstall password and tamper protection features are not currently supported for the Linux platform.&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;These features are currently implemented only for Windows and macOS operating systems.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;As correctly said by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/323731019"&gt;@ssingh32&lt;/a&gt;&amp;nbsp;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additionally, sharing a few details:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="138" data-end="188"&gt;&lt;STRONG data-start="138" data-end="188"&gt;Key details regarding this limitation include:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="190" data-end="960"&gt;
&lt;LI data-start="190" data-end="573"&gt;
&lt;P data-start="192" data-end="573"&gt;&lt;STRONG data-start="192" data-end="215"&gt;OS-Specific Design:&lt;/STRONG&gt; On Linux, the Cortex XDR agent relies on the operating system's inherent security controls. Since uninstallation and service management (such as &lt;CODE data-start="361" data-end="382"&gt;cytool runtime stop&lt;/CODE&gt;) require superuser (root or sudo) privileges, the agent is designed to allow these actions once those elevated permissions are met, without prompting for an additional XDR-specific password.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="574" data-end="778"&gt;
&lt;P data-start="576" data-end="778"&gt;&lt;STRONG data-start="576" data-end="600"&gt;Profile Limitations:&lt;/STRONG&gt; The &lt;EM data-start="605" data-end="621"&gt;Agent Security&lt;/EM&gt; section, which contains the tamper protection and uninstall password settings in the management console, is not available for Linux Agent Settings profiles.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="779" data-end="960"&gt;
&lt;P data-start="781" data-end="960"&gt;&lt;STRONG data-start="781" data-end="801"&gt;Feature Request:&lt;/STRONG&gt; This is a known product limitation and is currently tracked under feature request &lt;STRONG data-start="884" data-end="898"&gt;CXDR-I-267&lt;/STRONG&gt; (Linux XDR agent security settings for tampering protection).&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="962" data-end="990"&gt;&lt;STRONG data-start="962" data-end="990"&gt;Recommended Workarounds:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL data-start="992" data-end="1523"&gt;
&lt;LI data-start="992" data-end="1112"&gt;
&lt;P data-start="995" data-end="1112"&gt;&lt;STRONG data-start="995" data-end="1030"&gt;Restrict Administrative Access:&lt;/STRONG&gt; Ensure that root or sudo access is limited strictly to authorized personnel only.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1113" data-end="1322"&gt;
&lt;P data-start="1116" data-end="1322"&gt;&lt;STRONG data-start="1116" data-end="1142"&gt;Monitoring and Alerts:&lt;/STRONG&gt; Configure notification forwarding or Audit Log filters in the Cortex XDR console to alert administrators when the agent service is stopped (TYPE = AGENT SERVICE, SUB-TYPE = STOP).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1323" data-end="1523"&gt;
&lt;P data-start="1326" data-end="1523"&gt;&lt;STRONG data-start="1326" data-end="1347"&gt;External Logging:&lt;/STRONG&gt; Use local utilities such as &lt;CODE data-start="1376" data-end="1385"&gt;rsyslog&lt;/CODE&gt; to forward logs from &lt;CODE data-start="1407" data-end="1424"&gt;/var/log/traps/&lt;/CODE&gt; to an external log management system to ensure audit trails are preserved if the agent is removed.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;"mark this as a Solution".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Happy New Year!!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jan 2026 15:14:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/linux-agent-change-or-remove-without-password-bug/m-p/1244973#M8953</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-01-06T15:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: linux agent change or remove without password - bug ??</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/linux-agent-change-or-remove-without-password-bug/m-p/1245068#M8966</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;Happy new year for all.&lt;BR /&gt;And thanks for your responses&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/241098"&gt;@susekar&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/323731019"&gt;@ssingh32&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i'll try c&lt;SPAN&gt;onfigure notification forwarding or Audit Log filters in the Cortex XDR console to alert administrators when the agent service is stopped (TYPE = AGENT SERVICE, SUB-TYPE = STOP)...because sometimes someone with priv users can stop agent and i dont have alerts.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2026 10:33:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/linux-agent-change-or-remove-without-password-bug/m-p/1245068#M8966</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2026-01-07T10:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: linux agent change or remove without password - bug ??</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/linux-agent-change-or-remove-without-password-bug/m-p/1245069#M8967</link>
      <description>&lt;P&gt;but every time, machine is shutdown, agent stop...with this configuration, i'll get alot of false/positive.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2026 10:40:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/linux-agent-change-or-remove-without-password-bug/m-p/1245069#M8967</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2026-01-07T10:40:22Z</dc:date>
    </item>
  </channel>
</rss>

