- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-27-2025 01:04 PM
Have an interesting behavior that I was curious if anyone could clarify or validate. We recently enabled quarantine through malware profile/policy for VB Scripts Examination a feature just recently added to Cortex XDR v8.9. As such a hash that was previously added to block list quarantined a .vbs file by sha256 and an end-user contacted us reporting the behavior (file missing) and validated the script as known and benign. While remediating the issue a SOC analyst restored the file by sha256 and it appears in management audit log that at the same time the file restore occurred, an action also occurred to move the hash from block list to allow list. The SOC Analyst confirmed that they had not yet moved the sha256 to allow list from block list so what appears to have occurred is at the time of the file restore the sha256 was also added to allow list. Furthermore, the action center showed action for "restore quarantine" but no action for "add to allow list" only the management audit log has this activity.
I reviewed the Palo Alto Documentation Portal and could not locate mention of this behavior: Manage quarantined files • Cortex XDR 4.x Documentation • Palo Alto Networks documentation portal
Mgmt Audit Log {Redacted}:
20331886 Aug 27th 2025 19:04:20 soc.analyst@corp.com SOC Analyst Response Create Success Low Restore quarantined file with hash {HASH} on {HOST} and 13 other endpoints {IP}
20331885 Aug 27th 2025 19:04:20 soc.analyst@corp.com SOC Analyst Response Enable Success Low Enable and move 1 hash(es) from block list to allow list {IP}
08-27-2025 10:13 PM
That's probably an expected behaviour. When clicking "restore file" you'll get asked if you want to add the hash to the allow list.
08-27-2025 10:13 PM
That's probably an expected behaviour. When clicking "restore file" you'll get asked if you want to add the hash to the allow list.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!