<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Detect and Block Openclaw with XDR!? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/detect-and-block-openclaw-with-xdr/m-p/1247997#M9126</link>
    <description>&lt;P&gt;hello experts,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;my company is using XDR Pro, we noticed the importance of colleagues may use Openclaw...&amp;nbsp;&lt;BR /&gt;is there any way to detect or even block Openclaw from XDR or Firewall?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;SdG&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="NGFW" id="NGFW"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Feb 2026 05:00:01 GMT</pubDate>
    <dc:creator>SeanDeHarris</dc:creator>
    <dc:date>2026-02-12T05:00:01Z</dc:date>
    <item>
      <title>Detect and Block Openclaw with XDR!?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/detect-and-block-openclaw-with-xdr/m-p/1247997#M9126</link>
      <description>&lt;P&gt;hello experts,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;my company is using XDR Pro, we noticed the importance of colleagues may use Openclaw...&amp;nbsp;&lt;BR /&gt;is there any way to detect or even block Openclaw from XDR or Firewall?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;SdG&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="NGFW" id="NGFW"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2026 05:00:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/detect-and-block-openclaw-with-xdr/m-p/1247997#M9126</guid>
      <dc:creator>SeanDeHarris</dc:creator>
      <dc:date>2026-02-12T05:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: Detect and Block Openclaw with XDR!?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/detect-and-block-openclaw-with-xdr/m-p/1248043#M9127</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184443"&gt;@SeanDeHarris&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, you can detect and block OpenClaw using a combination of Cortex XDR and Palo Alto Networks Next-Generation Firewalls (NGFW). While Cortex XDR does not natively support Layer 7 URL blocking at the agent level, it offers several mechanisms to identify and stop the application and its associated network traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;1. Detection and Blocking via Cortex XDR&lt;/H4&gt;
&lt;P&gt;Because the Cortex XDR agent focuses on endpoint behavior and execution rather than direct web filtering, you should use the following methods:&lt;/P&gt;
&lt;H5&gt;Block the Executable (Global Block List):&lt;/H5&gt;
&lt;P&gt;To prevent the software from running, identify the SHA256 hash of the OpenClaw executable and add it to the &lt;STRONG&gt;Global Block List&lt;/STRONG&gt; in the Action Center.&lt;/P&gt;
&lt;H5&gt;Restriction Profiles:&lt;/H5&gt;
&lt;P&gt;You can use &lt;STRONG&gt;Restriction Profiles&lt;/STRONG&gt; to block the application by its file path (for example: &lt;CODE&gt;*\openclaw.exe&lt;/CODE&gt;).&lt;/P&gt;
&lt;H5&gt;Domain-type IOCs (Detection):&lt;/H5&gt;
&lt;P&gt;Although XDR cannot natively block the domain on its own, you can configure a &lt;STRONG&gt;Domain-type Indicator of Compromise (IOC)&lt;/STRONG&gt; for &lt;CODE&gt;openclaw.ai&lt;/CODE&gt;. This will generate an alert whenever an endpoint attempts to access that domain.&lt;/P&gt;
&lt;H5&gt;Host Firewall (IP-based):&lt;/H5&gt;
&lt;P&gt;You can use the &lt;STRONG&gt;Host Firewall module&lt;/STRONG&gt; to block outbound traffic to the specific IP addresses associated with OpenClaw. Note that this is less effective if the service uses dynamic IP addresses.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;2. Blocking via Palo Alto Networks Firewall (NGFW)&lt;/H4&gt;
&lt;P&gt;The firewall is the most effective tool for blocking the application's communication at the network perimeter.&lt;/P&gt;
&lt;H5&gt;URL Filtering:&lt;/H5&gt;
&lt;P&gt;Use a &lt;STRONG&gt;URL Filtering Profile&lt;/STRONG&gt; to block access to the &lt;CODE&gt;openclaw.ai&lt;/CODE&gt; domain directly.&lt;/P&gt;
&lt;H5&gt;External Dynamic Lists (EDL):&lt;/H5&gt;
&lt;P&gt;You can create or use an &lt;STRONG&gt;External Dynamic List (EDL)&lt;/STRONG&gt; integrated with your firewall to block malicious or unapproved domains and URLs systematically.&lt;/P&gt;
&lt;H5&gt;App-ID&lt;/H5&gt;
&lt;P&gt;Check for a specific &lt;STRONG&gt;App-ID&lt;/STRONG&gt; for OpenClaw (if available) to block the application traffic regardless of the port or protocol used.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;3. Investigation and Visibility&lt;/H4&gt;
&lt;P&gt;With your XDR Pro license, you can leverage the following for better visibility:&lt;/P&gt;
&lt;H5&gt;XQL Search&lt;/H5&gt;
&lt;P&gt;Use the &lt;STRONG&gt;Query Builder (XQL)&lt;/STRONG&gt; to search for network or DNS events related to OpenClaw across your environment.&lt;/P&gt;
&lt;H5&gt;Analytics&lt;/H5&gt;
&lt;P&gt;Ensure &lt;STRONG&gt;XDR Analytics&lt;/STRONG&gt; is enabled to detect abnormal network behaviors or large data uploads that might be associated with unapproved AI tools.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2026 14:04:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/detect-and-block-openclaw-with-xdr/m-p/1248043#M9127</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-02-12T14:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: Detect and Block Openclaw with XDR!?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/detect-and-block-openclaw-with-xdr/m-p/1248408#M9138</link>
      <description>&lt;P data-unlink="true"&gt;Update: Regarding the App-ID portion of Step 2, &lt;A href="https://beta.applipedia.paloaltonetworks.com/?search=openclaw" target="_self"&gt;OpenClaw is available via ACE&amp;nbsp;&lt;/A&gt; beginning 2/14/2026.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 00:46:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/detect-and-block-openclaw-with-xdr/m-p/1248408#M9138</guid>
      <dc:creator>TCoates</dc:creator>
      <dc:date>2026-02-18T00:46:49Z</dc:date>
    </item>
  </channel>
</rss>

