<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Predicting blocked alerts when switching Malware/Exploit modules from &amp;quot;Report&amp;quot; to &amp;quot;Block&amp;quot; in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/predicting-blocked-alerts-when-switching-malware-exploit-modules/m-p/1262826#M9519</link>
    <description>&lt;P data-path-to-node="4"&gt;Hi everyone,&lt;/P&gt;
&lt;P data-path-to-node="5"&gt;We are currently in the process of fine-tuning our Cortex XDR tenant. At the moment, we have several modules within our &lt;STRONG data-index-in-node="120" data-path-to-node="5"&gt;Malware&lt;/STRONG&gt; and &lt;STRONG data-index-in-node="132" data-path-to-node="5"&gt;Exploit&lt;/STRONG&gt; security profiles set to &lt;STRONG data-index-in-node="165" data-path-to-node="5"&gt;"Report"&lt;/STRONG&gt; mode.&lt;/P&gt;
&lt;P data-path-to-node="6"&gt;We are planning to harden our security posture and switch these modules to &lt;STRONG data-index-in-node="75" data-path-to-node="6"&gt;"Block"&lt;/STRONG&gt; mode. However, before making this change, we want to assess the potential impact on our environment to avoid disrupting legitimate operations or generating false-positive blockages.&lt;/P&gt;
&lt;P data-path-to-node="7"&gt;My question is: &lt;STRONG data-index-in-node="16" data-path-to-node="7"&gt;Is there a way to analyze the alerts and incidents currently in our console to predict exactly which ones &lt;I data-index-in-node="122" data-path-to-node="7"&gt;would have been blocked&lt;/I&gt; if those modules were already set to "Block"?&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Aug 2026 15:41:21 GMT</pubDate>
    <dc:creator>j.gamarra</dc:creator>
    <dc:date>2026-08-25T15:41:21Z</dc:date>
    <item>
      <title>Predicting blocked alerts when switching Malware/Exploit modules from "Report" to "Block"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/predicting-blocked-alerts-when-switching-malware-exploit-modules/m-p/1262826#M9519</link>
      <description>&lt;P data-path-to-node="4"&gt;Hi everyone,&lt;/P&gt;
&lt;P data-path-to-node="5"&gt;We are currently in the process of fine-tuning our Cortex XDR tenant. At the moment, we have several modules within our &lt;STRONG data-index-in-node="120" data-path-to-node="5"&gt;Malware&lt;/STRONG&gt; and &lt;STRONG data-index-in-node="132" data-path-to-node="5"&gt;Exploit&lt;/STRONG&gt; security profiles set to &lt;STRONG data-index-in-node="165" data-path-to-node="5"&gt;"Report"&lt;/STRONG&gt; mode.&lt;/P&gt;
&lt;P data-path-to-node="6"&gt;We are planning to harden our security posture and switch these modules to &lt;STRONG data-index-in-node="75" data-path-to-node="6"&gt;"Block"&lt;/STRONG&gt; mode. However, before making this change, we want to assess the potential impact on our environment to avoid disrupting legitimate operations or generating false-positive blockages.&lt;/P&gt;
&lt;P data-path-to-node="7"&gt;My question is: &lt;STRONG data-index-in-node="16" data-path-to-node="7"&gt;Is there a way to analyze the alerts and incidents currently in our console to predict exactly which ones &lt;I data-index-in-node="122" data-path-to-node="7"&gt;would have been blocked&lt;/I&gt; if those modules were already set to "Block"?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2026 15:41:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/predicting-blocked-alerts-when-switching-malware-exploit-modules/m-p/1262826#M9519</guid>
      <dc:creator>j.gamarra</dc:creator>
      <dc:date>2026-08-25T15:41:21Z</dc:date>
    </item>
  </channel>
</rss>

