Whitelist IP from XDR anlysis

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Whitelist IP from XDR anlysis

L0 Member

Hello,

 

We would ike to know if it is possible to create a list of IP's that will not be analysed by any of the XDR protection modules.We have a vulnerability scanning tool that uses all sorts of scripts to perform its tasks, At the moment, most of these scripts are blocked by Cortex because they look suspicious, which is true but not wanted in this situation.

 

We would like to create some sort of whitelist that prevents XDR from analyzing / inspecting / blocking traffic from these IP's. Is such a thing possible?

1 REPLY 1

L3 Networker

Hi @Kevin_Robers, We want to maintain security of environment while reducing operational impact. I believe obtaining some additional context on the alert criteria / scope will assist in determining the most effective path forward.  The following information will help to guide you on determining next steps: 

  • Have you completed vulnerability scans in your environment in the past, or this the first occurrence? If you have complete vulnerability scans without any operational impact, then this may be an opportunity to enhance the alert efficacy with content updates on your Cortex XDR agents. You will need to retrieve the endpoint support file from an endpoint in scope, and raise a support ticket for additional analysis.
  • Do the alerts in questions have a "detection" alert action? If so, then there should not be any change in the behavior of the file / process execution on the endpoint.  
  • Do the alerts in question have a “prevention” alert action?  If so, then you may consider adding the process / file path to an allow list / alert exception to continue operations. 
    • Similar to the first bullet, if the behavior in the alert originated from your vulnerability scanner and it is not a threat, then you can coordinate with support on the next steps (E.g. content update).

 

 

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!