MacOS Processes to be Allowlisted on EDR Deployment
Focus
Focus
Autonomous DEM

MacOS Processes to be Allowlisted on EDR Deployment

Table of Contents

MacOS Processes to be Allowlisted on EDR Deployment

Allow the agent processes on EDR for ADEM to function properly.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access (Managed by Panorama)
  • Prisma Access license
  • Autonomous DEM license
If you use a third-party EDR, you must allow the following MacOS agent processes on the EDR for ADEM to function properly. Examples of EDRs that require this include:
CrowdStrike
Trellix
SentinelOne
  • ADEM Agents 5.6 and Earlier
    MacOS Process
    ProcessProcess DescriptionUser/Permission Level
    /Applications/Access Experience.app/Contents/MacOS/crypterA support tool_panwdem (sudo)
    /Applications/Access Experience.app/Contents/Services/DemPathTestService.xpc/Contents/MacOS/mtrPath trace test for showing path visualization data on ADEM portal_panwdem (sudo)
    /Applications/Access Experience.app/Contents/Services/DemPathTestService.xpc/Contents/MacOS/DemPathTestServiceInvokes the mtr process for path traces._panwdem
    /Applications/Access Experience.app/Contents/Services/DemWebTestService.xpc/Contents/MacOS/DemWebTestServiceRuns the curl process._panwdem
    /Applications/Access Experience.app/Contents/Services/DemWebTestService.xpc/Contents/MacOS/curlApplication performance test using Curl_panwdem
    /Applications/Access Experience.app/Contents/Services/DemUpdateService.xpc/Contents/MacOS/DemUpdateServiceEndpoint DEM service software update managerroot
    /Applications/Access Experience.app/Contents/Services/DemNetworkTestService.xpc/Contents/MacOS/DemNetworkTestServiceRuns ICMP/TCP ping tests._panwdem
    /Applications/Access Experience.app/Contents/Services/DemCollectionService.xpc/Contents/MacOS/DemCollectionServiceCollects local system metrics such as cpu, memory, and wifi statistics._panwdem
    /Applications/Access Experience.app/Contents/Services/DemPortalService.xpc/Contents/MacOS/DemPortalServiceProvides connectivity to the ADEM portal for incoming configuration and transmission of test results._panwdem
    /Applications/Access Experience.app/Contents/Services/DemTransmissionService.xpc/Contents/MacOS/DemTransmissionServiceRuns periodically to collect test results from the other services and transmits them to the portal via the portal service._panwdem
    /Applications/Access Experience.app/Contents/MacOS/Access ExperienceThe main Access Experience UI that houses the End User Coaching and Self Service functionality. This is what runs when you click on a notification or launch from the MenuBar or /Applications folderLogged-in User
    /Applications/Access Experience.app/Contents/Library/Access Experience Menu.app/Contents/MacOS/Access Experience MenuThe macOS MenuBar application that provides the launcher for the Access Experience UI and provides Location Services integration for WiFi data collection when integrated with GlobalProtectLogged-in User
    /Applications/Access Experience.app/Contents/Services/DemPathTestService.xpc/Contents/MacOS/mtr-packetWorks with the mtr process to provide path trace functionality to the agent._panwdem (sudo)
    /Applications/Access Experience.app/Contents/Services/DemUserProxyService.xpc/Contents/MacOS/DemUserProxyServiceProvides a bridge between the ADEM services that run persistently with the _panwdem credentials to the logged-in users processes. This is required to deliver notifications to the user and real-time updates to the Access Experience UI for End User Coaching and Self Service._panwdem
    /Applications/Access Experience.app/Contents/Services/DemNetworkTestService.xpc/Contents/Frameworks/SPLPing.framework/Versions/A/SPLPingA library used by the agent to perform network ping testsN/A: This is a library used by DemNetworkTestService and does not execute independently.
    /Applications/Access Experience.app/Contents/Services/DemUpdateService.xpc/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/MacOS/fileopPart of the agent updater mechanismroot
    /Applications/Access Experience.app/Contents/Services/DemUpdateService.xpc/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/MacOS/AutoupdatePart of the agent updater mechanismroot
    /Applications/Access Experience.app/Contents/Services/DemUpdateService.xpc/Contents/Frameworks/Sparkle.framework/Versions/A/SparklePart of the agent updater mechanismroot
    /etc/ sudoers.d/palo_alto_networks_demA file listing processes that require sudo accessN/A: This is a configuration file and not an executable, so permission levels do not apply.
    /Applications/Access Experience.app/Contents/Services/DemAnalyticsService.xpc/Contents/MacOS/DemAnalyticsServicePerforms data collection and processing for the End User Coaching and Self Service features._panwdem
  • ADEM Agent 5.7
    MacOS Process
    ProcessProcess DescriptionUser/Permission Level
    /Applications/Access Experience.app/Contents/MacOS/crypterA support tool_panwdem (sudo)
    /Applications/Access Experience.app/Contents/Services/DemPathTestService.xpc/Contents/MacOS/mtrPath trace test for showing path visualization data on ADEM portal_panwdem (sudo)
    /Applications/Access Experience.app/Contents/Services/DemPathTestService.xpc/Contents/MacOS/DemPathTestServiceInvokes the mtr process for path traces._panwdem
    /Applications/Access Experience.app/Contents/Services/DemWebTestService.xpc/Contents/MacOS/DemWebTestServiceRuns the curl process._panwdem
    /Applications/Access Experience.app/Contents/Services/DemWebTestService.xpc/Contents/MacOS/curlApplication performance test using Curl_panwdem
    /Applications/Access Experience.app/Contents/Services/DemUpdateService.xpc/Contents/MacOS/DemUpdateServiceEndpoint DEM service software update managerroot
    /Applications/Access Experience.app/Contents/Services/DemNetworkTestService.xpc/Contents/MacOS/DemNetworkTestServiceRuns ICMP/TCP ping tests._panwdem
    /Applications/Access Experience.app/Contents/Services/DemCollectionService.xpc/Contents/MacOS/DemCollectionServiceCollects local system metrics such as cpu, memory, and wifi statistics._panwdem
    /Applications/Access Experience.app/Contents/Services/DemPortalService.xpc/Contents/MacOS/DemPortalServiceProvides connectivity to the ADEM portal for incoming configuration and transmission of test results._panwdem
    /Applications/Access Experience.app/Contents/Services/DemTransmissionService.xpc/Contents/MacOS/DemTransmissionServiceRuns periodically to collect test results from the other services and transmits them to the portal via the portal service._panwdem
    /Applications/Access Experience.app/Contents/MacOS/Access ExperienceThe main Access Experience UI that houses the End User Coaching and Self Service functionality. This is what runs when you click on a notification or launch from the MenuBar or /Applications folderLogged-in User
    /Applications/Access Experience.app/Contents/Library/Access Experience Menu.app/Contents/MacOS/Access Experience MenuThe macOS MenuBar application that provides the launcher for the Access Experience UI and provides Location Services integration for WiFi data collection when integrated with GlobalProtectLogged-in User
    /Applications/Access Experience.app/Contents/Services/DemPathTestService.xpc/Contents/MacOS/mtr-packetWorks with the mtr process to provide path trace functionality to the agent._panwdem (sudo)
    /Applications/Access Experience.app/Contents/Services/DemUserProxyService.xpc/Contents/MacOS/DemUserProxyServiceProvides a bridge between the ADEM services that run persistently with the _panwdem credentials to the logged-in users processes. This is required to deliver notifications to the user and real-time updates to the Access Experience UI for End User Coaching and Self Service._panwdem
    /Applications/Access Experience.app/Contents/Services/DemNetworkTestService.xpc/Contents/Frameworks/SPLPing.framework/Versions/A/SPLPingA library used by the agent to perform network ping testsN/A: This is a library used by DemNetworkTestService and does not execute independently.
    /Applications/Access Experience.app/Contents/Services/DemUpdateService.xpc/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/MacOS/fileopPart of the agent updater mechanismroot
    /Applications/Access Experience.app/Contents/Services/DemUpdateService.xpc/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/MacOS/AutoupdatePart of the agent updater mechanismroot
    /Applications/Access Experience.app/Contents/Services/DemUpdateService.xpc/Contents/Frameworks/Sparkle.framework/Versions/A/SparklePart of the agent updater mechanismroot
    /etc/ sudoers.d/palo_alto_networks_demA file listing processes that require sudo accessN/A: This is a configuration file and not an executable, so permission levels do not apply.
    /Applications/Access Experience.app/Contents/Services/DemAnalyticsService.xpc/Contents/MacOS/DemAnalyticsServicePerforms data collection and processing for the End User Coaching and Self Service features._panwdem
    Processes to be allowlisted to monitor LAN health when local network access is disabled
    /Applications/Access Experience.app/Contents/Services/DemLocalNetworkTestService.xpc/Contents/MacOS/DemLocalNetworkTestServiceDedicated process for running ICMP/TCP ping tests to local network targets, such as the default gateway._panwdem
    /Applications/Access Experience.app/Contents/Services/DemPathTestService.xpc/Contents/MacOS/local-network/mtrLocal network specific path trace test for showing path visualization data on the ADEM portal._panwdem (sudo)
    /Applications/Access Experience.app/Contents/Services/DemPathTestService.xpc/Contents/MacOS/local-network/mtr-packet
    Works with the local network specific mtr process to provide path trace functionality to the agent.
    _panwdem (sudo)