<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Local Analysis and Exceptions in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/local-analysis-and-exceptions/m-p/1255860#M9375</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/205511299"&gt;@J.Motz&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN&gt;Why Standard Hash Exclusions and Disable Prevention Rules (DPR) Fail:&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;When Microsoft Word executes macros, it frequently creates temporary files (such as &lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;~WRD0001.tmp&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;.asd&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt; files, or &lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;Normal.dotm&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt;) with randomized filenames and dynamically changing hashes.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;As a result, standard hash-based exclusions are often ineffective because each newly generated file may have a different hash value, preventing the exclusion from consistently matching the file.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Additionally, Disable Prevention Rules (DPR) are reactive in nature. They are applied during a later stage of the evaluation process to prevent remediation actions such as file quarantine or process termination. However, DPRs do not prevent security modules, such as Local Analysis, from inspecting and evaluating the files.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Because of this behavior, applying a DPR to &lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;WinWord.exe&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt; or to the macro file hash itself may not prevent the file from being analyzed and can still result in application delays, freezes, or blocking behavior during the inspection process.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Option 1 - Feature Vector Hash (fvHash) Support Exceptions (SUEX)&lt;/H3&gt;
&lt;P&gt;-Contact PaloAlto Cortex XDR TAC support.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN&gt;Option 2: Proactive Legacy Agent Exceptions with Granular Wildcards&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Unlike reactive DPRs, Legacy Agent Exceptions are proactive and instruct the agent to completely bypass scanning of the specified file or path, helping to eliminate both blocking and application freezes.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Instead of excluding the entire network share, configure a Legacy Agent Exception targeting the specific module and use narrow path wildcards to limit the scope of the exclusion.&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL start="1" data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;In the Cortex XDR console, navigate to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Settings &amp;gt; Exception Configurations &amp;gt; Legacy Agent Exceptions&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Click &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;+ Add Rule&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Set the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Platform&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Windows&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Set the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Module&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Office Files and Macros Examination&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; (or &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Portable Executable and DLL Examination&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; if DLLs are being generated).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Define the folder structure on the network share using wildcard patterns to target only the required macro files.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Examples:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL data-spread="true"&gt;
&lt;LI&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Targeting macro-enabled Word templates:&amp;nbsp;&lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;\\your-share\folder\*\*.dotm&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Targeting specific filename patterns:&lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;\\your-share\folder\~*.tmp&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="isSelectedEnd"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Important:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; If excluding a specific directory structure on the share, ensure the path ends with a wildcard (&lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;*&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt;) so that all dynamically generated files and subfolders are covered.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Example:&amp;nbsp;&lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;\\your-share\specificmacrofolder\*'&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;CODE dir="ltr"&gt;&lt;/CODE&gt;&lt;CODE dir="ltr"&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN&gt;Option 3: Digitally Sign the Macros:&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;A more robust and security-aligned approach is to digitally sign the macros using a trusted enterprise code-signing certificate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL start="1" data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;Ensure the certificate is deployed and trusted on all relevant endpoints.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;In the Cortex XDR console, edit the active &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Malware Security Profile&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Under the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Signer Allow List&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, add the signer or publisher certificate name.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;This allows signed macro files to execute without relying on path-based exclusions or constantly changing file hashes.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN&gt;Option 4: Targeted Policy Adjustments (Module Disablement):&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;If macro development or execution is limited to a specific group of systems (such as VDI hosts, Citrix servers, or designated business units), consider creating a dedicated policy.&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL start="1" data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;Navigate to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Policy Management &amp;gt; Profiles &amp;gt; Malware Profiles&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Duplicate an existing profile or create a new one (for example, &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Citrix_WinWord_Allow_Macros&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Locate the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Office Files and Macros Examination&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; module.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Set the action to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Allow&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; or &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Disabled&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, depending on the requirement.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Create a corresponding &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Prevention Rule&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; and assign the customized Malware Profile only to the approved endpoints or server groups.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;This approach enables macro execution where required while maintaining stricter protection policies across the rest of the environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jun 2026 14:19:31 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-06-10T14:19:31Z</dc:date>
    <item>
      <title>Local Analysis and Exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/local-analysis-and-exceptions/m-p/1255823#M9373</link>
      <description>&lt;P&gt;Hey,&lt;BR /&gt;we are struggling with the following Case with understanding local Analysis, Macros and writing a useful exceptions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Local Analysis is alerting on a WinWord.exe with "Macro(s) in Winword.exe". The Macro is only mentioned by hash.&lt;/P&gt;
&lt;P&gt;Exception with&amp;nbsp;Disable Prevention Rules&amp;nbsp;&lt;SPAN&gt;for local analysis on the macro hashes are not working, similarly on Winword.exe itself.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;All Files are accessed on a share drive.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, our Problem is that we ideally want to just exclude the macro hash somehow. But since this doesn´t work what is the alternative?&amp;nbsp;&lt;BR /&gt;Excluding the whole Path seems to excessive.&amp;nbsp;&lt;BR /&gt;Maybe reducing some "Parameters" that influence the local analysis to get the analysis score down.&amp;nbsp;&lt;BR /&gt;Or is there some other simple or alternative solution we did not think of.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you in advance for your response.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 09:26:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/local-analysis-and-exceptions/m-p/1255823#M9373</guid>
      <dc:creator>J.Motz</dc:creator>
      <dc:date>2026-06-10T09:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: Local Analysis and Exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/local-analysis-and-exceptions/m-p/1255860#M9375</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/205511299"&gt;@J.Motz&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN&gt;Why Standard Hash Exclusions and Disable Prevention Rules (DPR) Fail:&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;When Microsoft Word executes macros, it frequently creates temporary files (such as &lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;~WRD0001.tmp&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;.asd&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt; files, or &lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;Normal.dotm&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt;) with randomized filenames and dynamically changing hashes.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;As a result, standard hash-based exclusions are often ineffective because each newly generated file may have a different hash value, preventing the exclusion from consistently matching the file.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Additionally, Disable Prevention Rules (DPR) are reactive in nature. They are applied during a later stage of the evaluation process to prevent remediation actions such as file quarantine or process termination. However, DPRs do not prevent security modules, such as Local Analysis, from inspecting and evaluating the files.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Because of this behavior, applying a DPR to &lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;WinWord.exe&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt; or to the macro file hash itself may not prevent the file from being analyzed and can still result in application delays, freezes, or blocking behavior during the inspection process.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Option 1 - Feature Vector Hash (fvHash) Support Exceptions (SUEX)&lt;/H3&gt;
&lt;P&gt;-Contact PaloAlto Cortex XDR TAC support.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN&gt;Option 2: Proactive Legacy Agent Exceptions with Granular Wildcards&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Unlike reactive DPRs, Legacy Agent Exceptions are proactive and instruct the agent to completely bypass scanning of the specified file or path, helping to eliminate both blocking and application freezes.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Instead of excluding the entire network share, configure a Legacy Agent Exception targeting the specific module and use narrow path wildcards to limit the scope of the exclusion.&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL start="1" data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;In the Cortex XDR console, navigate to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Settings &amp;gt; Exception Configurations &amp;gt; Legacy Agent Exceptions&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Click &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;+ Add Rule&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Set the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Platform&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Windows&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Set the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Module&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Office Files and Macros Examination&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; (or &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Portable Executable and DLL Examination&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; if DLLs are being generated).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Define the folder structure on the network share using wildcard patterns to target only the required macro files.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Examples:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL data-spread="true"&gt;
&lt;LI&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Targeting macro-enabled Word templates:&amp;nbsp;&lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;\\your-share\folder\*\*.dotm&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Targeting specific filename patterns:&lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;\\your-share\folder\~*.tmp&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="isSelectedEnd"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Important:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; If excluding a specific directory structure on the share, ensure the path ends with a wildcard (&lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;*&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt;) so that all dynamically generated files and subfolders are covered.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Example:&amp;nbsp;&lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;\\your-share\specificmacrofolder\*'&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;CODE dir="ltr"&gt;&lt;/CODE&gt;&lt;CODE dir="ltr"&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN&gt;Option 3: Digitally Sign the Macros:&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;A more robust and security-aligned approach is to digitally sign the macros using a trusted enterprise code-signing certificate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL start="1" data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;Ensure the certificate is deployed and trusted on all relevant endpoints.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;In the Cortex XDR console, edit the active &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Malware Security Profile&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Under the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Signer Allow List&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, add the signer or publisher certificate name.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;This allows signed macro files to execute without relying on path-based exclusions or constantly changing file hashes.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN&gt;Option 4: Targeted Policy Adjustments (Module Disablement):&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;If macro development or execution is limited to a specific group of systems (such as VDI hosts, Citrix servers, or designated business units), consider creating a dedicated policy.&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL start="1" data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;Navigate to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Policy Management &amp;gt; Profiles &amp;gt; Malware Profiles&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Duplicate an existing profile or create a new one (for example, &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Citrix_WinWord_Allow_Macros&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Locate the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Office Files and Macros Examination&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; module.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Set the action to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Allow&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; or &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Disabled&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, depending on the requirement.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Create a corresponding &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Prevention Rule&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; and assign the customized Malware Profile only to the approved endpoints or server groups.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;This approach enables macro execution where required while maintaining stricter protection policies across the rest of the environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 14:19:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/local-analysis-and-exceptions/m-p/1255860#M9375</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-06-10T14:19:31Z</dc:date>
    </item>
  </channel>
</rss>

