how I add exclusion based on for an specific process (license.exe) for specific endpoint

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

how I add exclusion based on for an specific process (license.exe) for specific endpoint

L1 Bithead

Hi family 

How I add an  exclusion based on for a specific process allow  (license.exe) for specific endpoint on cortex xdr. wildfire are blocking this process many times so i want to allow for this service for specific endpoint. 

thanks, and regards.

1 REPLY 1

L4 Transporter

Hi @Prashanta, thanks for reaching us using the Live Community.

 

This is the overall process:

 

- Create a new Exceptions Security Profile: https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-a-Legac...

 

- Create a new legacy exception rule in Settings - Exceptions Configuration.

We recommend to select only the protection module that is blocking the process, you can see it in the Alert details.

Select the previously created Exceptions Profile.

jmazzeo_0-1711547160016.png

 

- Now create the Policy Rule to apply the profile to the required Endpoint.

You can copy your production policy with right click - Save as New

jmazzeo_1-1711547395186.png

Change the Exceptions Profile to the new created one with the exception assigned.

jmazzeo_2-1711547450439.png

And then select the endpoint in the Target menu using the filters.

jmazzeo_3-1711547504297.png

 

Please check it and let us know how it goes.

 

If this post answers your question, please mark it as the solution.

JM
  • 498 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!