Quarantined File Automatically Moved to Allow List from Block List after File Restore Action

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Quarantined File Automatically Moved to Allow List from Block List after File Restore Action

L0 Member

Have an interesting behavior that I was curious if anyone could clarify or validate. We recently enabled quarantine through malware profile/policy for VB Scripts Examination a feature just recently added to Cortex XDR v8.9. As such a hash that was previously added to block list quarantined a .vbs file by sha256 and an end-user contacted us reporting the behavior (file missing) and validated the script as known and benign. While remediating the issue a SOC analyst restored the file by sha256 and it appears in management audit log that at the same time the file restore occurred, an action also occurred to move the hash from block list to allow list. The SOC Analyst confirmed that they had not yet moved the sha256 to allow list from block list so what appears to have occurred is at the time of the file restore the sha256 was also added to allow list. Furthermore, the action center showed action for "restore quarantine" but no action for "add to allow list" only the management audit log has this activity. 

 

I reviewed the Palo Alto Documentation Portal and could not locate mention of this behavior: Manage quarantined files • Cortex XDR 4.x Documentation • Palo Alto Networks documentation portal

 

Mgmt Audit Log {Redacted}:

20331886  Aug 27th 2025 19:04:20  soc.analyst@corp.com  SOC Analyst  Response  Create    Success  Low    Restore quarantined file with hash {HASH} on {HOST} and 13 other endpoints {IP}

 

20331885  Aug 27th 2025 19:04:20  soc.analyst@corp.com  SOC  Analyst  Response  Enable    Success  Low    Enable and move 1 hash(es) from block list to allow list  {IP}  

1 accepted solution

Accepted Solutions

L3 Networker

Hi @Austin_Arzon 

That's probably an expected behaviour. When clicking "restore file" you'll get asked if you want to add the hash to the allow list.

micomi_0-1756357986017.png

 

View solution in original post

1 REPLY 1

L3 Networker

Hi @Austin_Arzon 

That's probably an expected behaviour. When clicking "restore file" you'll get asked if you want to add the hash to the allow list.

micomi_0-1756357986017.png

 

  • 1 accepted solution
  • 265 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!