<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to exclude a legitimate signed process from Anti-Ransomware Protection (Suspicious File Modification) in block mode? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-exclude-a-legitimate-signed-process-from-anti-ransomware/m-p/1256443#M7412</link>
    <description>&lt;P&gt;Hi all, We get a false positive on Cortex XSIAM: Alert: Suspicious File Modification Module: Anti-Ransomware Protection Process: jpconsole.exe (OpenText Blazon), signed by Open Text Corporation, WildFire = Benign It is a legitimate app that modifies many files normally, so it looks like ransomware. We are in Report mode now and want to move to Block mode, but we are afraid the process will be killed. Question: How do I exclude this signed process so Anti-Ransomware does not block it in block mode? In Legacy Agent Exceptions there is no Anti-Ransomware module, and the path/signer allow-list only appears under other modules. Is there a way to allow-list by path or signer for ransomware? Thanks.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Jun 2026 05:53:44 GMT</pubDate>
    <dc:creator>H.Eldessouki</dc:creator>
    <dc:date>2026-06-16T05:53:44Z</dc:date>
    <item>
      <title>How to exclude a legitimate signed process from Anti-Ransomware Protection (Suspicious File Modification) in block mode?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-exclude-a-legitimate-signed-process-from-anti-ransomware/m-p/1256443#M7412</link>
      <description>&lt;P&gt;Hi all, We get a false positive on Cortex XSIAM: Alert: Suspicious File Modification Module: Anti-Ransomware Protection Process: jpconsole.exe (OpenText Blazon), signed by Open Text Corporation, WildFire = Benign It is a legitimate app that modifies many files normally, so it looks like ransomware. We are in Report mode now and want to move to Block mode, but we are afraid the process will be killed. Question: How do I exclude this signed process so Anti-Ransomware does not block it in block mode? In Legacy Agent Exceptions there is no Anti-Ransomware module, and the path/signer allow-list only appears under other modules. Is there a way to allow-list by path or signer for ransomware? Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2026 05:53:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-exclude-a-legitimate-signed-process-from-anti-ransomware/m-p/1256443#M7412</guid>
      <dc:creator>H.Eldessouki</dc:creator>
      <dc:date>2026-06-16T05:53:44Z</dc:date>
    </item>
  </channel>
</rss>

