<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can Prisma Cloud Defender attempt to connect to ports? in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/can-prisma-cloud-defender-attempt-to-connect-to-ports/m-p/1238402#M1531</link>
    <description>&lt;P&gt;Hello!&amp;nbsp;&lt;/P&gt;
&lt;DIV class="c-message_kit__gutter"&gt;
&lt;DIV class="c-message_kit__gutter__right" role="presentation" data-qa="message_content"&gt;
&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;DIV class="p-rich_text_section"&gt;I don't think a defender can perform that command.&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;
&lt;DIV class="c-message_kit__gutter"&gt;
&lt;DIV class="c-message_kit__gutter__right" role="presentation" data-qa="message_content"&gt;
&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;DIV class="p-rich_text_section"&gt;Some defender logs would provide more clarity and additional details to troubleshoot the issue further.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="c-message_actions__container c-message__actions" role="group"&gt;
&lt;DIV class="c-message_actions__group" role="group" aria-label="Message actions" data-qa="message-actions"&gt;
&lt;DIV class="container__z3l0C"&gt;
&lt;DIV class="c-message_kit__gutter"&gt;
&lt;DIV class="c-message_kit__gutter__right" role="presentation" data-qa="message_content"&gt;
&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;DIV class="p-rich_text_section"&gt;I would recommend opening a support case for further assistance.&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="c-message_actions__container c-message__actions" role="group"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="c-message_actions__container c-message__actions" role="group"&gt;
&lt;DIV class="c-message_actions__group" role="group" aria-label="Message actions" data-qa="message-actions"&gt;
&lt;DIV class="container__z3l0C"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Fri, 19 Sep 2025 19:51:41 GMT</pubDate>
    <dc:creator>LMegrelis</dc:creator>
    <dc:date>2025-09-19T19:51:41Z</dc:date>
    <item>
      <title>Can Prisma Cloud Defender attempt to connect to ports?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/can-prisma-cloud-defender-attempt-to-connect-to-ports/m-p/1238358#M1530</link>
      <description>&lt;P&gt;I understood that Prisma Cloud Defender does not directly attempt to connect to ports or perform scans,&lt;/P&gt;
&lt;P&gt;but it seems to have executed the &lt;CODE&gt;curl -X OPTIONS &lt;A href="http://localhost:8355" target="_blank"&gt;http://localhost:8355&lt;/A&gt;&lt;/CODE&gt; command on the tomcat shutdown port.&lt;/P&gt;
&lt;P&gt;Since such a command was executed, there are daily logs of it being blocked by the tomcat shutdown port.&lt;/P&gt;
&lt;P&gt;Please tell me the reason why Prisma Cloud Defender performs such a command:&amp;nbsp;&lt;CODE&gt;curl -X OPTIONS &lt;A href="http://localhost:8355" target="_blank"&gt;http://localhost:8355&lt;/A&gt;&lt;/CODE&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2025 05:07:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/can-prisma-cloud-defender-attempt-to-connect-to-ports/m-p/1238358#M1530</guid>
      <dc:creator>S.Choi879310</dc:creator>
      <dc:date>2025-09-19T05:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: Can Prisma Cloud Defender attempt to connect to ports?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/can-prisma-cloud-defender-attempt-to-connect-to-ports/m-p/1238402#M1531</link>
      <description>&lt;P&gt;Hello!&amp;nbsp;&lt;/P&gt;
&lt;DIV class="c-message_kit__gutter"&gt;
&lt;DIV class="c-message_kit__gutter__right" role="presentation" data-qa="message_content"&gt;
&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;DIV class="p-rich_text_section"&gt;I don't think a defender can perform that command.&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;
&lt;DIV class="c-message_kit__gutter"&gt;
&lt;DIV class="c-message_kit__gutter__right" role="presentation" data-qa="message_content"&gt;
&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;DIV class="p-rich_text_section"&gt;Some defender logs would provide more clarity and additional details to troubleshoot the issue further.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="c-message_actions__container c-message__actions" role="group"&gt;
&lt;DIV class="c-message_actions__group" role="group" aria-label="Message actions" data-qa="message-actions"&gt;
&lt;DIV class="container__z3l0C"&gt;
&lt;DIV class="c-message_kit__gutter"&gt;
&lt;DIV class="c-message_kit__gutter__right" role="presentation" data-qa="message_content"&gt;
&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;DIV class="p-rich_text_section"&gt;I would recommend opening a support case for further assistance.&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="c-message_actions__container c-message__actions" role="group"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="c-message_actions__container c-message__actions" role="group"&gt;
&lt;DIV class="c-message_actions__group" role="group" aria-label="Message actions" data-qa="message-actions"&gt;
&lt;DIV class="container__z3l0C"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 19 Sep 2025 19:51:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/can-prisma-cloud-defender-attempt-to-connect-to-ports/m-p/1238402#M1531</guid>
      <dc:creator>LMegrelis</dc:creator>
      <dc:date>2025-09-19T19:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can Prisma Cloud Defender attempt to connect to ports?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/can-prisma-cloud-defender-attempt-to-connect-to-ports/m-p/1241465#M1544</link>
      <description>&lt;P&gt;I too observed this in my EKS setup where prisma defender is running as container&amp;nbsp; , where these calls and logs are through out .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Upon checking with security team&amp;nbsp; some upgrades were performed, but none seem to have stopped it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was thinking of blocking this via network or network policies ,rather than blocking at the application or mesh level.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in my observation there is scan utility with in who is performing this .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any one attempted&amp;nbsp; ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Nov 2025 06:06:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/can-prisma-cloud-defender-attempt-to-connect-to-ports/m-p/1241465#M1544</guid>
      <dc:creator>mailvk23</dc:creator>
      <dc:date>2025-11-08T06:06:53Z</dc:date>
    </item>
  </channel>
</rss>

