<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR Pro – Does it scan USB devices upon insertion? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-does-it-scan-usb-devices-upon-insertion/m-p/1253475#M9311</link>
    <description>&lt;P data-end="1875" data-start="1865"&gt;Hi team,&lt;/P&gt;
&lt;P data-end="1962" data-start="1883"&gt;I would like to confirm the behavior of Cortex XDR Pro regarding USB devices:&lt;/P&gt;
&lt;UL data-end="2294" data-start="1970"&gt;
&lt;LI data-end="2071" data-start="1970" data-section-id="kjxu0c"&gt;Does Cortex XDR perform any automatic malware scan when a USB device is connected to an endpoint?&lt;/LI&gt;
&lt;LI data-end="2201" data-start="2074" data-section-id="1ahwmla"&gt;If not, what protections are applied at connection time (e.g., device control, behavioral detection, execution monitoring)?&lt;/LI&gt;
&lt;LI data-end="2289" data-start="2204" data-section-id="eqtep6"&gt;Is scanning of removable media only performed during periodic or on-demand scans?&lt;/LI&gt;
&lt;LI data-end="2289" data-start="2204" data-section-id="eqtep6"&gt;Or at least, any configuration inside the agent settings profile?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="2391" data-start="2297"&gt;Appreciate your clarification and any best practices for securing USB usage with Cortex XDR.&lt;/P&gt;</description>
    <pubDate>Tue, 05 May 2026 16:43:18 GMT</pubDate>
    <dc:creator>QuestionAb</dc:creator>
    <dc:date>2026-05-05T16:43:18Z</dc:date>
    <item>
      <title>Cortex XDR Pro – Does it scan USB devices upon insertion?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-does-it-scan-usb-devices-upon-insertion/m-p/1253475#M9311</link>
      <description>&lt;P data-end="1875" data-start="1865"&gt;Hi team,&lt;/P&gt;
&lt;P data-end="1962" data-start="1883"&gt;I would like to confirm the behavior of Cortex XDR Pro regarding USB devices:&lt;/P&gt;
&lt;UL data-end="2294" data-start="1970"&gt;
&lt;LI data-end="2071" data-start="1970" data-section-id="kjxu0c"&gt;Does Cortex XDR perform any automatic malware scan when a USB device is connected to an endpoint?&lt;/LI&gt;
&lt;LI data-end="2201" data-start="2074" data-section-id="1ahwmla"&gt;If not, what protections are applied at connection time (e.g., device control, behavioral detection, execution monitoring)?&lt;/LI&gt;
&lt;LI data-end="2289" data-start="2204" data-section-id="eqtep6"&gt;Is scanning of removable media only performed during periodic or on-demand scans?&lt;/LI&gt;
&lt;LI data-end="2289" data-start="2204" data-section-id="eqtep6"&gt;Or at least, any configuration inside the agent settings profile?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="2391" data-start="2297"&gt;Appreciate your clarification and any best practices for securing USB usage with Cortex XDR.&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2026 16:43:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-does-it-scan-usb-devices-upon-insertion/m-p/1253475#M9311</guid>
      <dc:creator>QuestionAb</dc:creator>
      <dc:date>2026-05-05T16:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Pro – Does it scan USB devices upon insertion?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-does-it-scan-usb-devices-upon-insertion/m-p/1253545#M9314</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/804344437"&gt;@QuestionAb&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="249" data-start="0"&gt;Cortex XDR Pro does not perform an automatic malware scan of a USB device immediately upon connection or mounting. This specific functionality (Scan-on-Connect) is a known product limitation and is currently tracked under feature request CXDR-I-305.&lt;/P&gt;
&lt;P data-end="249" data-start="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="379" data-start="251"&gt;However, Cortex XDR provides a multi-layered defense to secure USB usage through execution-based prevention and access controls.&lt;/P&gt;
&lt;P data-end="379" data-start="251"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="548" data-start="381"&gt;&lt;STRONG data-end="426" data-start="381"&gt;1. Protections Applied at Connection Time&lt;/STRONG&gt;&lt;BR data-end="429" data-start="426" /&gt;While a full scan is not triggered, the following protections are active at the time of connection or file interaction:&lt;/P&gt;
&lt;UL data-end="1414" data-start="550"&gt;
&lt;LI data-end="805" data-start="550" data-section-id="18w8ckl"&gt;&lt;STRONG data-end="571" data-start="552"&gt;Device Control:&lt;/STRONG&gt; This module allows you to block, allow, or set USB storage devices to "Read-Only" mode based on device classes (Disk Drive, Portable Device, CD-ROM) or specific hardware descriptors such as Vendor ID, Product ID, and Serial Number.&lt;/LI&gt;
&lt;LI data-end="1070" data-start="806" data-section-id="ksw5r3"&gt;&lt;STRONG data-end="847" data-start="808"&gt;Behavioral Threat Protection (BTP):&lt;/STRONG&gt; Cortex XDR includes a dedicated BTP module to identify and block malicious or spoofed USB devices, such as "Rubber Ducky" HIDs (Human Interface Devices) that masquerade as keyboards or mice to execute malicious commands.&lt;/LI&gt;
&lt;LI data-end="1245" data-start="1071" data-section-id="f4g18z"&gt;&lt;STRONG data-end="1109" data-start="1073"&gt;Real-time &amp;amp; On-Write Protection:&lt;/STRONG&gt; The agent performs real-time scanning and behavioral analysis the moment a file is accessed, copied, or executed from the USB device.&lt;/LI&gt;
&lt;LI data-end="1414" data-start="1246" data-section-id="1rb1luq"&gt;&lt;STRONG data-end="1273" data-start="1248"&gt;Execution Monitoring:&lt;/STRONG&gt; Any file attempting to run from the USB is subject to the full suite of malware protection modules, including Local Analysis and WildFire.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1530" data-start="1416"&gt;&lt;STRONG data-end="1449" data-start="1416"&gt;2. Available Scanning Methods&lt;/STRONG&gt;&lt;BR data-end="1452" data-start="1449" /&gt;Scanning of removable media can be performed through the following mechanisms:&lt;/P&gt;
&lt;UL data-end="2051" data-start="1532"&gt;
&lt;LI data-end="1693" data-start="1532" data-section-id="n4jr2q"&gt;&lt;STRONG data-end="1553" data-start="1534"&gt;Periodic Scans:&lt;/STRONG&gt; You must explicitly enable the option &lt;EM data-end="1621" data-start="1592"&gt;Scan Removable Media Drives&lt;/EM&gt; within the Malware Security Profile under the Periodic Scan settings.&lt;/LI&gt;
&lt;LI data-end="1908" data-start="1694" data-section-id="18h41r"&gt;&lt;STRONG data-end="1727" data-start="1696"&gt;Manual/User-Initiated Scan:&lt;/STRONG&gt; If the &lt;EM data-end="1766" data-start="1735"&gt;End-user Initiated Local Scan&lt;/EM&gt; option is enabled in the Malware Security Profile, users can right-click a USB drive in Windows Explorer and select &lt;EM data-end="1905" data-start="1883"&gt;Scan with Cortex XDR&lt;/EM&gt;.&lt;/LI&gt;
&lt;LI data-end="2051" data-start="1909" data-section-id="y5wy0d"&gt;&lt;STRONG data-end="1937" data-start="1911"&gt;On-Demand System Scan:&lt;/STRONG&gt; Full system scans initiated from the Cortex XDR console can be configured to include attached removable drives.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="2141" data-start="2053"&gt;&lt;STRONG data-end="2082" data-start="2053"&gt;3. Configuration Profiles&lt;/STRONG&gt;&lt;BR data-end="2085" data-start="2082" /&gt;Relevant settings are located in the following profiles:&lt;/P&gt;
&lt;UL data-is-last-node="" data-is-only-node="" data-end="2677" data-start="2143"&gt;
&lt;LI data-end="2355" data-start="2143" data-section-id="9rxn45"&gt;&lt;STRONG data-end="2174" data-start="2145"&gt;Malware Security Profile:&lt;/STRONG&gt;
&lt;UL data-end="2355" data-start="2179"&gt;
&lt;LI data-end="2265" data-start="2179" data-section-id="1d1vozl"&gt;General Settings: Enable &lt;EM data-end="2237" data-start="2206"&gt;End-user Initiated Local Scan&lt;/EM&gt; to allow manual scanning.&lt;/LI&gt;
&lt;LI data-end="2355" data-start="2268" data-section-id="sxfizu"&gt;Periodic Scan: Enable &lt;EM data-end="2307" data-start="2292"&gt;Periodic Scan&lt;/EM&gt; and then check &lt;EM data-end="2352" data-start="2323"&gt;Scan Removable Media Drives&lt;/EM&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI data-end="2534" data-start="2357" data-section-id="1eyj10l"&gt;&lt;STRONG data-end="2386" data-start="2359"&gt;Device Control Profile:&lt;/STRONG&gt;&lt;BR data-end="2389" data-start="2386" /&gt;Used to define baseline "Allow" or "Block" actions for different USB device types and to configure specific exceptions based on hardware IDs.&lt;/LI&gt;
&lt;LI data-is-last-node="" data-end="2677" data-start="2536" data-section-id="1d3u4iv"&gt;&lt;STRONG data-end="2562" data-start="2538"&gt;Restriction Profile:&lt;/STRONG&gt;&lt;BR data-end="2565" data-start="2562" /&gt;Can be used to restrict the execution of specific file types (like executables) directly from removable media.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 06 May 2026 18:46:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-pro-does-it-scan-usb-devices-upon-insertion/m-p/1253545#M9314</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-05-06T18:46:15Z</dc:date>
    </item>
  </channel>
</rss>

