Windows Processes to be Allowlisted on EDR Deployments
Focus
Focus
Autonomous DEM

Windows Processes to be Allowlisted on EDR Deployments

Table of Contents

Windows Processes to be Allowlisted on EDR Deployments

Allow the agent processes on EDR for ADEM to function properly.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access (Managed by Panorama)
  • Prisma Access license
  • Autonomous DEM license
If you use a third-party EDR, you must allow the following Windows agent processes on the EDR for ADEM to function properly. Examples of EDRs that require this include:
  • CrowdStrike
  • Trellix
  • SentinelOne
  • ADEM Agents 5.3 and Earlier
    Windows Process
    ProcessProcess DescriptionUser/Permission Level
    C:\Program Files\Palo Alto Networks\DEM\DEMAgentProcess.exeThe main agent process that provides portal connectivity and test coordinationLocal System
    C:\Program Files\Palo Alto Networks\DEM\bin\BMTR.exePerforms TCP path traces.Local System
    C:\Program Files\Palo Alto Networks\DEM\bin\curl.exeApplication Performance test using Curl.Network Service
    C:\Program Files\Palo Alto Networks\DEM\bin\mtr.exeInvokes the mtr process for path traces.Network Service
    C:\Program Files\Palo Alto Networks\DEM\bin\mtr-packet.exePath trace test for showing path visualization data on ADEM portal.Network Service
    C:\Program Files\Palo Alto Networks\DEM\bin\tcping.exeNetwork performance test for applications using TCP ping.Network Service
    C:\Program Files\Palo Alto Networks\DEM\DEMAgentService.exeLauncher for the main agent process. It isolates the integration with the Windows Service subsystem.Local System
    C:\Program Files\Palo Alto Networks\DEM\DEMPortalProcess.exeCommunicates with the portal on behalf of the agent. It is isolated in a separate process so it can run with suitable permissions.Network Service
    C:\Program Files\Palo Alto Networks\DEM\deployment\DEMUpdateService.exeProvides upgrade functionality.Local System
    "C:\Program Files\Palo Alto Networks\DEM\Feature-Self-Service\Access Experience.exe"The Windows Status Tray application that provides the launcher for the Access Experience UI and raises desktop notifications for the user.Logged-in User
    C:\Program Files\Palo Alto Networks\DEM\Feature-Self-Service\createdump.exePart of the application runtime required by Windows.N/A: This is a code-level dependency that does not get executed.
    C:\Program Files\Palo Alto Networks\DEM\Feature-Self-Service\DEMAnalyticsProcess.exePerforms data collection and processing for the End User Coaching and Self Service features.Local Service
  • ADEM Agent 5.4
    Windows Process
    ProcessProcess DescriptionUser/Permission Level
    C:\Program Files\Palo Alto Networks\DEM\DEMAgentProcess.exeThe main agent process that provides portal connectivity and test coordination.Local System
    C:\Program Files\Palo Alto Networks\DEM\DEMBios.exeA utility that extracts the BIOS serial number for use by the update service.Local System
    C:\Program Files\Palo Alto Networks\DEM\bin\BMTR.exePerforms TCP path traces.Local System
    C:\Program Files\Palo Alto Networks\DEM\bin\curl.exeApplication Performance test using Curl.Network Service
    C:\Program Files\Palo Alto Networks\DEM\bin\mtr.exeInvokes the mtr process for path traces.Network Service
    C:\Program Files\Palo Alto Networks\DEM\bin\mtr-packet.exePath trace test for showing path visualization data on ADEM portal.Network Service
    C:\Program Files\Palo Alto Networks\DEM\bin\tcping.exeNetwork performance test for applications using TCP ping.Network Service
    C:\Program Files\Palo Alto Networks\DEM\DEMAgentService.exeLauncher for the main agent process. It isolates the integration with the Windows Service subsystem.Local System
    C:\Program Files\Palo Alto Networks\DEM\DEMPortalProcess.exeCommunicates with the portal on behalf of the agent. It is isolated in a separate process so it can run with suitable permissions.Network Service
    C:\Program Files\Palo Alto Networks\DEM\deployment\DEMUpdateService.exeProvides upgrade functionality.Local System
    C:\Program Files\Palo Alto Networks\DEM\EProxy.exeUtility tool for debugging purpose, doesn't get executed.N/A: This is a code-level dependency that does not get executed.
    "C:\Program Files\Palo Alto Networks\DEM\Feature-Self-Service\Access Experience.exe"The Windows Status Tray application that provides the launcher for the Access Experience UI and raises desktop notifications for the user.Logged-in User
    C:\Program Files\Palo Alto Networks\DEM\Feature-Self-Service\createdump.exePart of the application runtime required by Windows.N/A: This is a code-level dependency that does not get executed.
    C:\Program Files\Palo Alto Networks\DEM\Feature-Self-Service\DEMAnalyticsProcess.exePerforms data collection and processing for the End User Coaching and Self Service features.Local Service
  • ADEM Agent 5.5
    Windows Process
    ProcessProcess DescriptionUser/Permission Level
    C:\Program Files\Palo Alto Networks\DEM\DEMAgentProcess.exeThe main agent process that provides portal connectivity and test coordination.Local System
    C:\Program Files\Palo Alto Networks\DEM\DEMAgentCLI.exeUtility tool for debugging purpose, doesn't get executed.N/A: This is a code-level dependency that does not get executed.
    C:\Program Files\Palo Alto Networks\DEM\DEMBios.exeA utility that extracts the BIOS serial number for use by the update service.Local System
    C:\Program Files\Palo Alto Networks\DEM\BMTR.exePerforms TCP path traces.Local System
    C:\Program Files\Palo Alto Networks\DEM\Crypter.exeUtility tool for debugging purpose, doesn't get executed.N/A: This is a code-level dependency that does not get executed.
    C:\Program Files\Palo Alto Networks\DEM\curl.exeApplication Performance test using Curl.Network Service
    C:\Program Files\Palo Alto Networks\DEM\EProxy.exeUtility tool for debugging purpose, doesn't get executed.N/A: This is a code-level dependency that does not get executed.
    C:\Program Files\Palo Alto Networks\DEM\mtr.exeInvokes the mtr process for path traces.Network Service
    C:\Program Files\Palo Alto Networks\DEM\mtr-packet.exePath trace test for showing path visualization data on ADEM portal.Network Service
    C:\Program Files\Palo Alto Networks\DEM\tcping.exeNetwork performance test for applications using TCP ping.Network Service
    C:\Program Files\Palo Alto Networks\DEM\DEMAgentService.exeLauncher for the main agent process. It isolates the integration with the Windows Service subsystem.Local System
    C:\Program Files\Palo Alto Networks\DEM\DEMPortalProcess.exeCommunicates with the portal on behalf of the agent. It is isolated in a separate process so it can run with suitable permissions.Network Service
    C:\Program Files\Palo Alto Networks\DEM\deployment\DEMUpdateService.exeProvides upgrade functionality.Local System
    "C:\Program Files\Palo Alto Networks\DEM\Feature-Self-Service\Access Experience.exe"The Windows Status Tray application that provides the launcher for the Access Experience UI and raises desktop notifications for the user.Logged-in User
    C:\Program Files\Palo Alto Networks\DEM\Feature-Self-Service\DEMAnalyticsProcess.exePerforms data collection and processing for the End User Coaching and Self Service features.Local Service
  • ADEM Agent 5.6
    Windows Process
    ProcessProcess DescriptionUser/Permission Level
    C:\Program Files\Palo Alto Networks\DEM\NativeMessagingHost.exeCommunicates with the real-user monitor extension.Local System
    C:\Program Files\Palo Alto Networks\DEM\DEMAgentProcess.exeThe main agent process that provides portal connectivity and test coordination.Local System
    C:\Program Files\Palo Alto Networks\DEM\DEMAgentCLI.exeUtility tool for debugging purpose, doesn't get executed.N/A: This is a code-level dependency that does not get executed.
    C:\Program Files\Palo Alto Networks\DEM\DEMBios.exeA utility that extracts the BIOS serial number for use by the update service.Local System
    C:\Program Files\Palo Alto Networks\DEM\BMTR.exePerforms TCP path traces.Local System
    C:\Program Files\Palo Alto Networks\DEM\Crypter.exeUtility tool for debugging purpose, doesn't get executed.N/A: This is a code-level dependency that does not get executed.
    C:\Program Files\Palo Alto Networks\DEM\curl.exeApplication Performance test using Curl.Network Service
    C:\Program Files\Palo Alto Networks\DEM\EProxy.exeUtility tool for debugging purpose, doesn't get executed.N/A: This is a code-level dependency that does not get executed.
    C:\Program Files\Palo Alto Networks\DEM\mtr.exeInvokes the mtr process for path traces.Network Service
    C:\Program Files\Palo Alto Networks\DEM\mtr-packet.exePath trace test for showing path visualization data on ADEM portal.Network Service
    C:\Program Files\Palo Alto Networks\DEM\tcping.exeNetwork performance test for applications using TCP ping.Network Service
    C:\Program Files\Palo Alto Networks\DEM\DEMAgentService.exeLauncher for the main agent process. It isolates the integration with the Windows Service subsystem.Local System
    C:\Program Files\Palo Alto Networks\DEM\DEMPortalProcess.exeCommunicates with the portal on behalf of the agent. It is isolated in a separate process so it can run with suitable permissions.Network Service
    C:\Program Files\Palo Alto Networks\DEM\deployment\DEMUpdateService.exeProvides upgrade functionality.Local System
    "C:\Program Files\Palo Alto Networks\DEM\Feature-Self-Service\Access Experience.exe"The Windows Status Tray application that provides the launcher for the Access Experience UI and raises desktop notifications for the user. Logged-in User
    C:\Program Files\Palo Alto Networks\DEM\Feature-Self-Service\DEMAnalyticsProcess.exePerforms data collection and processing for the End User Coaching and Self Service features.Local Service
  • ADEM Agent 5.7
    Windows Process
    ProcessProcess DescriptionUser/Permission Level
    C:\Program Files\Palo Alto Networks\DEM\NativeMessagingHost.exeCommunicates with the real-user monitor extension.Local System
    C:\Program Files\Palo Alto Networks\DEM\DEMAgentProcess.exeThe main agent process that provides portal connectivity and test coordination.Local System
    C:\Program Files\Palo Alto Networks\DEM\DEMAgentCLI.exeUtility tool for debugging purpose, doesn't get executed.N/A: This is a code-level dependency that does not get executed.
    C:\Program Files\Palo Alto Networks\DEM\DEMBios.exeA utility that extracts the BIOS serial number for use by the update service.Local System
    C:\Program Files\Palo Alto Networks\DEM\BMTR.exePerforms TCP path traces.Local System
    C:\Program Files\Palo Alto Networks\DEM\Crypter.exeUtility tool for debugging purpose, doesn't get executed.N/A: This is a code-level dependency that does not get executed.
    C:\Program Files\Palo Alto Networks\DEM\curl.exeApplication Performance test using Curl.Network Service
    C:\Program Files\Palo Alto Networks\DEM\EProxy.exeUtility tool for debugging purpose, doesn't get executed.N/A: This is a code-level dependency that does not get executed.
    C:\Program Files\Palo Alto Networks\DEM\mtr.exeInvokes the mtr process for path traces.Network Service
    C:\Program Files\Palo Alto Networks\DEM\mtr-packet.exePath trace test for showing path visualization data on ADEM portal.Network Service
    C:\Program Files\Palo Alto Networks\DEM\tcping.exeNetwork performance test for applications using TCP ping.Network Service
    C:\Program Files\Palo Alto Networks\DEM\DEMAgentService.exeLauncher for the main agent process. It isolates the integration with the Windows Service subsystem.Local System
    C:\Program Files\Palo Alto Networks\DEM\DEMPortalProcess.exeCommunicates with the portal on behalf of the agent. It is isolated in a separate process so it can run with suitable permissions.Network Service
    C:\Program Files\Palo Alto Networks\DEM\deployment\DEMUpdateService.exeProvides upgrade functionality.Local System
    "C:\Program Files\Palo Alto Networks\DEM\Feature-Self-Service\Access Experience.exe"The Windows Status Tray application that provides the launcher for the Access Experience UI and raises desktop notifications for the user. Logged-in User
    C:\Program Files\Palo Alto Networks\DEM\Feature-Self-Service\DEMAnalyticsProcess.exePerforms data collection and processing for the End User Coaching and Self Service features.Local Service
    Processes to be Allowlisted to Monitor LAN Health When Local Network Access is Blocked
    C:\Program Files\Palo Alto Networks\DEM\DEMLocalNetworkTestProcess.exeDedicated process for local network ping tests.Local System
    C:\Program Files\Palo Alto Networks\DEM\BMTR-Local.exe
    Local network specific utility to perform TCP path traces.
    Local System
    C:\Program Files\Palo Alto Networks\DEM\LocalNetwork\mtr.exeLocal network specific utility to perform ICMP path traces.Network Service
    C:\Program Files\Palo Alto Networks\DEM\LocalNetwork\mtr-packet.exeWorks with the local network specific mtr process to provide path trace functionality to the agent.Network Service