For the complete documentation index, see llms.txt. This page is also available as Markdown.

Disable Injection and Prevention Rules overview

The Disable Injection and Prevention Rules API lets you add and manage rules in Cortex XDR that define process-level exceptions, bypassing prevention modules and injection. These rules can be applied only to endpoints running Cortex XDR agent version 7.9 or later.

This API allows you to:

  • Fetch existing Disable Injection and Prevention rules with filtering and pagination.

  • Add new Disable Injection and Prevention rules to generate a temporary exception to bypass a process from prevention modules and injections.

  • Disable existing rules by their IDs.

Required license: Cortex Cloud Posture Management or Cortex Cloud Runtime Security

Last updated

Was this helpful?