Does adding legit windows binary hash to the allow list increase load on the XDR agent?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Does adding legit windows binary hash to the allow list increase load on the XDR agent?

L0 Member

Does adding legit windows binary hash to the allow list increase load on the XDR agent?

1 REPLY 1

L3 Networker

Hello @Abhishemh ,

 

Greetings for the day!

 

Adding a legitimate Windows binary hash to the Allow List does not increase the load on the Cortex XDR agent; in fact, it is a recommended method to decrease agent resource consumption and mitigate CPU spikes.

How the Allow List Impacts Agent Performance

When a file hash is added to the Allow List, it is synchronized to the endpoint and stored in a local database called hash_overrides.db.

 

  • Bypassing Intensive Scans: When the agent encounters a binary that is on the allow list, it identifies the "Benign" override and explicitly skips intensive security flows, including Local Analysis (LA) and WildFire (WF) uploads/queries.
  • Mitigating CPU Spikes: Large binaries require significant CPU resources for the agent to calculate hashes (SHA256, MD5) and perform inspections. By adding these to the Allow List, the agent avoids these costly calculations, which significantly reduces performance overhead, especially in environments where multiple replicas of the same large binary are executed simultaneously (e.g., containerized environments).
  • Reducing Network and Server Load: Using the allow list reduces the volume of communication between the agent and the Cortex XDR management console by preventing unnecessary file uploads and verdict queries.

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".

 

Happy New year!!

 

Thanks & Regards,
S. Subashkar Sekar

  • 410 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!