Legacy agent exception and Disable prevention rule

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Legacy agent exception and Disable prevention rule

L2 Linker

What is the difference between Legacy agent exception and Disable prevention rules?

 

This was asked in another discussion but the answer does not resolve the question asked (https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exception-and-exclusion-tips-amp-trick-b... )

 

Thanks

Danny

1 accepted solution

Accepted Solutions

L1 Bithead

Disable prevention rules are more granular compared to legacy agent exceptions. 

Legacy agent exceptions Target the hole module like pe dll examination where as disable prevention rules would Target specific protections within that..like we can do wildfire detection, wildfire post detection, local analysis etc..

Disable prevention rules generate an alert even after allowing the activities where as legacy agent exceptions mostly don't generate alerts and allow a process to run.(E.g global behavior protection based legacy exception or credential protection module related ones generate alerts and other PE dll examination module based legacy agent exceptions don't generate alerts.

That's all I can remember for now 😉 

View solution in original post

4 REPLIES 4

L4 Transporter

Hi @DannyMulheran, thanks for reaching us using the Live Community.

 

The Disable Prevention Rules applies to agents only from version 7.9 and above.

jmazzeo_0-1715256308817.png

 

The Legacy Agent Exceptions also applies to older agent versions.

 

If this post answers your question, please mark it as the solution.

JM

L1 Bithead

Disable prevention rules are more granular compared to legacy agent exceptions. 

Legacy agent exceptions Target the hole module like pe dll examination where as disable prevention rules would Target specific protections within that..like we can do wildfire detection, wildfire post detection, local analysis etc..

Disable prevention rules generate an alert even after allowing the activities where as legacy agent exceptions mostly don't generate alerts and allow a process to run.(E.g global behavior protection based legacy exception or credential protection module related ones generate alerts and other PE dll examination module based legacy agent exceptions don't generate alerts.

That's all I can remember for now 😉 

Thanks, really appreciate the reply.

Thanks JM, your response is appreciated.

  • 1 accepted solution
  • 512 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!