- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-12-2022 12:55 AM
Hi,
I want to add an exception for an in house app that the xdr keeps blocking. I tried adding a global exception as outlined here - https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/exception...
However I dont have the option to create an alert exception in the right click menu. I am an admin in our xdr.
How can i create an exception?
07-12-2022 12:55 PM
Hi Daniel_Itenberg,
The context menu changes depending on the alert you select. If the alert is a Behavioral Threat Protection (BTP) alert, you will have the "Create Alert Exception" option under Manage Alert. If the alert is a Local Malware Analysis alert, you will have the "Add initiator SHA256 to Allow list" option under Manage Alert. Can you please confirm the source of the alert and the alert name? This will tell us what kind of alert you are trying to create an exception for.
07-12-2022 07:03 PM
The broadsword approach to the solution is to add it to the Global Allow List : https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-respo...
08-10-2022 02:55 AM
I want to completely exclude examination of said process from all endpoints in my organisation. adding to the allow list dosent help because the sha256 is different everytime the program is run. I know there is a way to add global exceptions to the local malware analysis module, however there is no such option available to me, and that's what i need
08-10-2022 09:08 AM
Kindly refer to our webinar --> around 12:15 timeframe https://live.paloaltonetworks.com/t5/cortex-xdr-webinars/cortex-xdr-customer-success-webinar-alert-t...
04-09-2024 05:58 PM
After your Add initiator SHA256 to Allow list, can you still revert back if needed? Remove the SHA256 from the allow list?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!