<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Suspicious URL detection by cortex in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-url-detection-by-cortex/m-p/548536#M111994</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Will cortex be able to detect if there is any malicious URL clicked by user?&lt;/P&gt;
&lt;P&gt;Also, would like to know how cortex detect the ransomware attack.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sakshi Seth&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jul 2023 10:55:07 GMT</pubDate>
    <dc:creator>Seth_Sakshi</dc:creator>
    <dc:date>2023-07-07T10:55:07Z</dc:date>
    <item>
      <title>Suspicious URL detection by cortex</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-url-detection-by-cortex/m-p/548536#M111994</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Will cortex be able to detect if there is any malicious URL clicked by user?&lt;/P&gt;
&lt;P&gt;Also, would like to know how cortex detect the ransomware attack.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sakshi Seth&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 10:55:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-url-detection-by-cortex/m-p/548536#M111994</guid>
      <dc:creator>Seth_Sakshi</dc:creator>
      <dc:date>2023-07-07T10:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious URL detection by cortex</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-url-detection-by-cortex/m-p/548567#M112003</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/188171"&gt;@Seth_Sakshi&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Cortex XDR isn't meant to do any web filtering. I think it's assumed that you have your endpoints routing traffic through another PAN product (firewall, GlobalProtect, Prisma Access) and that these other products are already providing that coverage for you in the event you need it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With ransomware detection there's a few different methods that XDR will use. Obviously if the file is known to be malicious it'll just block the execution, it'll look at the processes from a behavioral analysis aspect, and then it deploys (very small) decoy files across every single directory.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The overview that I've attached is slightly older, but it'll give you a good fundamental overview.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 13:49:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-url-detection-by-cortex/m-p/548567#M112003</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-07-07T13:49:35Z</dc:date>
    </item>
  </channel>
</rss>

