<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does adding legit windows binary hash to the allow list increase load on the XDR agent? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-adding-legit-windows-binary-hash-to-the-allow-list-increase/m-p/1245921#M9016</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1523781643"&gt;@Abhishemh&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Adding a legitimate Windows binary hash to the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Allow List&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;does not increase the load on the Cortex XDR agent; in fact, it is a recommended method to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;decrease&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;agent resource consumption and mitigate CPU spikes.&lt;/P&gt;
&lt;H3&gt;How the Allow List Impacts Agent Performance&lt;/H3&gt;
&lt;P&gt;When a file hash is added to the Allow List, it is synchronized to the endpoint and stored in a local database called&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;hash_overrides.db&lt;/CODE&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Bypassing Intensive Scans:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;When the agent encounters a binary that is on the allow list, it identifies the "Benign" override and explicitly&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;skips&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;intensive security flows, including&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Local Analysis (LA)&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;WildFire (WF)&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;uploads/queries.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Mitigating CPU Spikes:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Large binaries require significant CPU resources for the agent to calculate hashes (SHA256, MD5) and perform inspections. By adding these to the Allow List, the agent avoids these costly calculations, which significantly reduces performance overhead, especially in environments where multiple replicas of the same large binary are executed simultaneously (e.g., containerized environments).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Reducing Network and Server Load:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Using the allow list reduces the volume of communication between the agent and the Cortex XDR management console by preventing unnecessary file uploads and verdict queries.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Happy New year!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
    <pubDate>Mon, 19 Jan 2026 15:11:29 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-01-19T15:11:29Z</dc:date>
    <item>
      <title>Does adding legit windows binary hash to the allow list increase load on the XDR agent?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-adding-legit-windows-binary-hash-to-the-allow-list-increase/m-p/1245664#M9014</link>
      <description>&lt;P&gt;Does adding legit windows binary hash to the allow list increase load on the XDR agent?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jan 2026 13:56:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-adding-legit-windows-binary-hash-to-the-allow-list-increase/m-p/1245664#M9014</guid>
      <dc:creator>Abhishemh</dc:creator>
      <dc:date>2026-01-15T13:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: Does adding legit windows binary hash to the allow list increase load on the XDR agent?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-adding-legit-windows-binary-hash-to-the-allow-list-increase/m-p/1245921#M9016</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1523781643"&gt;@Abhishemh&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Adding a legitimate Windows binary hash to the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Allow List&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;does not increase the load on the Cortex XDR agent; in fact, it is a recommended method to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;decrease&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;agent resource consumption and mitigate CPU spikes.&lt;/P&gt;
&lt;H3&gt;How the Allow List Impacts Agent Performance&lt;/H3&gt;
&lt;P&gt;When a file hash is added to the Allow List, it is synchronized to the endpoint and stored in a local database called&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;hash_overrides.db&lt;/CODE&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Bypassing Intensive Scans:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;When the agent encounters a binary that is on the allow list, it identifies the "Benign" override and explicitly&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;skips&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;intensive security flows, including&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Local Analysis (LA)&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;WildFire (WF)&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;uploads/queries.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Mitigating CPU Spikes:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Large binaries require significant CPU resources for the agent to calculate hashes (SHA256, MD5) and perform inspections. By adding these to the Allow List, the agent avoids these costly calculations, which significantly reduces performance overhead, especially in environments where multiple replicas of the same large binary are executed simultaneously (e.g., containerized environments).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Reducing Network and Server Load:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Using the allow list reduces the volume of communication between the agent and the Cortex XDR management console by preventing unnecessary file uploads and verdict queries.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Happy New year!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jan 2026 15:11:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-adding-legit-windows-binary-hash-to-the-allow-list-increase/m-p/1245921#M9016</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-01-19T15:11:29Z</dc:date>
    </item>
  </channel>
</rss>

