Add a New Exceptions Security Profile
In Cortex XDR, an exceptions security profile apply to
specific groups of endpoints.
You
can configure exceptions that apply to specific groups of endpoints
or you can Add a Global Endpoint Policy Exception.
Use the following workflow to create an endpoint-specific exception:
- Add a new profile.
- FromCortexXDR, selectand select whether toEndpointsPolicy ManagementPreventionProfiles+ New ProfileCreate NeworImport from Filea new profile.New imported profiles are added and not replaced.
- Select the platform to which the profile applies andExceptionsas the profile type.
- ClickNext.
- Define the basic settings.
- Enter a uniqueProfile Nameto identify the profile. The name can contain only letters, numbers, or spaces, and must be no more than 30 characters. The name you choose will be visible from the list of profiles when you configure a policy rule.
- To provide additional context for the purpose or business reason that explains why you are creating the profile, enter a profileDescription. For example, you might include an incident identification number or a link to a help desk ticket.
- Configure the exceptions profile.To configure a Process Exception:
- Select the operating system.
- Enter the name of the process.
- Select one or more Endpoint Protection Modules that will allow this process to run. The modules displayed on the list are the modules relevant to the operating system defined for this profile. To apply the process exception on all security modules,Select all. To apply the process exception on all exploit security modules, selectDisable Injection.
- Click the adjacent arrow.
- After you’ve added all processes, clickCreate.You can return to the Process Exception profile from theEndpoints Profilepage at any point and edit the settings, for example if you want to add or remove more security modules.
To configure a Support Exception:- Import thejsonfile you received from Palo Alto Networks support team by either browsing for it in your files or by dragging and dropping the file on the page.
- ClickCreate.
To configure module specific exceptions relevant for the selected profile platform:- Behavioral Threat Protection Rule Exception—When you view an alert for a Behavioral Threat event which you want to allow in your network from now on, right-click the alert andCreate alert exception. Review the alert data (Platform and Rule name) and select from the following options as needed.-CGO hash—Causality Group Owner (CGO) hash value.-CGO signer—CGO signer entity (for Windows and Mac only).-CGO process path—Directory path of the CGO process.-CGO command arguments—CGO command arguments. This option is available only ifCGO process pathis selected, and only if you are usingCortexXDRAgent 7.5 or later on your endpoints. After selecting this option, check the full path of each relevant command argument within quote marks. You can edit the displayed paths if needed.FromException Scope, selectProfileand clickCreate.
- Digital Signer Exception—When you view an alert for a Digital Signer Restriction which you want to allow in your network from now on, right-click the alert andCreate alert exception.CortexXDRdisplays the alert data (Platform, Signer, and Generating Alert ID). SelectException Scope: Profileand select the exception profile name. ClickAdd.
- Java Deserialization Exception—When you identify a Suspicious Input Deserialization alert that you believe to be benign and want to suppress future alerts, right-click the alert andCreate alert exception.CortexXDRdisplays the alert data (Platform, Process, Java executable, and Generating Alert ID). SelectException Scope: Profileand select the exception profile name. ClickAdd.
- Local File Threat Examination Exception—When you view an alert for a PHP file which you want to allow in your network from now on, right-click the alert andCreate alert exception.CortexXDRdisplays the alert data (Process, Path, and Hash). SelectException Scope: Profileand select the exception profile name. ClickAdd
- Gatekeeper Enhancement Exception—When you view a Gatekeeper Enhancement security alert for a bundle or specific source-child combination you want to allow in your network from now on, right-click the alert andCreate alert exception.CortexXDRdisplays the alert data (Platform, Source Process, Target Process, and Alert ID). SelectException Scope: Profileand select the exception profile name. ClickAdd. This exception allowsCortexXDRto continue enforcing the Gatekeeper Enhancement protection module on the source process running other child processes.
At any point, you can click theGenerating Alert IDto return to the original alert from which the exception was originated. You cannot edit module specific exceptions. - If you want to remove an exceptions profile from your network, go to theProfilespage, right-click and selectDelete
Recommended For You
Recommended Videos
Recommended videos not found.