<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What does it mean Prevented(Blocked) by the Agent XDR? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-does-it-mean-prevented-blocked-by-the-agent-xdr/m-p/428110#M980</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/187524"&gt;@david.hernandez&lt;/a&gt;&amp;nbsp; XDR offers a multi-layer approach to secure your environment, so it is important to understand the &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/analysis-and-protection-flow.html" target="_self"&gt;file analysis and protection flow&lt;/A&gt; (&lt;EM&gt;E.g.&amp;nbsp; Phase 3: Hash Verdict Determination&lt;/EM&gt;). Additional considerations are to &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-files/review-wildfire-analysis-details" target="_self"&gt;review WildFire analysis details&lt;/A&gt;, and if you know the WildFire is incorrect, then you can report an incorrect verdict to Palo Alto Networks to request a verdict change.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 20 Aug 2021 14:57:58 GMT</pubDate>
    <dc:creator>WSeldenIII</dc:creator>
    <dc:date>2021-08-20T14:57:58Z</dc:date>
    <item>
      <title>What does it mean Prevented(Blocked) by the Agent XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-does-it-mean-prevented-blocked-by-the-agent-xdr/m-p/427985#M976</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;What does the Prevented (Blocked) action of the XDR agent mean?&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;Does the user receive/see any notification?&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;And, how do I prevent the XDR agent from blocking that key artifact?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;Thank you,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;David.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 05:41:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-does-it-mean-prevented-blocked-by-the-agent-xdr/m-p/427985#M976</guid>
      <dc:creator>david.hernandez</dc:creator>
      <dc:date>2021-08-20T05:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: What does it mean Prevented(Blocked) by the Agent XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-does-it-mean-prevented-blocked-by-the-agent-xdr/m-p/428062#M977</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on the policy XDR agent blocks any file which has a verdict as Malware, When the file is blocked user should receive a message from XDR agent pop up window and the same will be reported as alert in XDR Console. You can disable blocking of a file with malware verdict by adding it to allow list or you can also set policies to stop blocking files in a location or type/extension etc based on your requirement - check out this &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-files/manage-file-execution.html" target="_blank" rel="noopener"&gt;link for allow list&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 09:45:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-does-it-mean-prevented-blocked-by-the-agent-xdr/m-p/428062#M977</guid>
      <dc:creator>sramesh-7</dc:creator>
      <dc:date>2021-08-20T09:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: What does it mean Prevented(Blocked) by the Agent XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-does-it-mean-prevented-blocked-by-the-agent-xdr/m-p/428069#M978</link>
      <description>&lt;P&gt;Hi Sramesh-7,&lt;/P&gt;&lt;P&gt;Thank you for your quick response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I added the file to the allow List, which it comes from WildFire Malware.&lt;/P&gt;&lt;P&gt;Some days later, I get a new incident only involved with this Key artifact but from&amp;nbsp;Local Analysis Malware (although the key artifact is in the allow list).&lt;BR /&gt;The threat intelligence&amp;nbsp;catalog it as malware.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that the behaviour expected? What can I do?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;/P&gt;&lt;P&gt;David.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 10:25:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-does-it-mean-prevented-blocked-by-the-agent-xdr/m-p/428069#M978</guid>
      <dc:creator>david.hernandez</dc:creator>
      <dc:date>2021-08-20T10:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: What does it mean Prevented(Blocked) by the Agent XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-does-it-mean-prevented-blocked-by-the-agent-xdr/m-p/428110#M980</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/187524"&gt;@david.hernandez&lt;/a&gt;&amp;nbsp; XDR offers a multi-layer approach to secure your environment, so it is important to understand the &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/analysis-and-protection-flow.html" target="_self"&gt;file analysis and protection flow&lt;/A&gt; (&lt;EM&gt;E.g.&amp;nbsp; Phase 3: Hash Verdict Determination&lt;/EM&gt;). Additional considerations are to &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-files/review-wildfire-analysis-details" target="_self"&gt;review WildFire analysis details&lt;/A&gt;, and if you know the WildFire is incorrect, then you can report an incorrect verdict to Palo Alto Networks to request a verdict change.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 14:57:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-does-it-mean-prevented-blocked-by-the-agent-xdr/m-p/428110#M980</guid>
      <dc:creator>WSeldenIII</dc:creator>
      <dc:date>2021-08-20T14:57:58Z</dc:date>
    </item>
  </channel>
</rss>

