cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.

Who Me Too'd this solution

L2 Linker

Hi @JoaoMachado ,

 

Thank you for reaching out to Palo Alto Live Community.

 

You can try to define specific files and folders to exclude from examination and allow for execution. In the Policy you want this to apply to, it's under 'Malware Security Profile' > 'Files/Folders in Allow List'.

 

Here is the link to the documentation that explains the process:

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-a-New-M...

 

You may have to do this for each component - portable executables, office docs, scans.  I've included a few screenshots where you would do this.  The screenshots also have examples of the formatting.

 

PE's and DLL

dbahuguna_0-1698312767028.png

 

Scans

dbahuguna_1-1698312767030.png

 

Hope this helps!

 

Please mark the response as "Accept as Solution" if it answers your query.

View solution in original post

Who Me Too'd this solution