> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security.md).

# Endpoint security

- [Endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection.md): This topic provides an overview of traditional endpoint protection versus the protection of endpoints using Cortex Cloud.
- [Malware protection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/malware-protection.md): Cortex Cloud prevents malware attacks and provides protection on endpoints based on the different operating systems.
- [Exploit protection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/exploit-protection.md): Cortex Cloud prevents exploit attempts and provides protection on endpoints based on the different operating systems.
- [File analysis and protection flow](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/file-analysis-and-protection-flow.md): The Cortex XDR agent utilizes advanced multi-method protection and prevention techniques to protect from both known and unknown malware and software exploits.
- [Endpoint protection capabilities](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/endpoint-protection-capabilities.md): The endpoint protection capabilities vary depending on the platform (operating system) that is used on each of your endpoints.
- [Endpoint protection modules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/endpoint-protection-modules.md): Security modules are activated for your endpoints depending on the chosen security profile and the operating system on the endpoint.
- [Processes protected by exploit security policy](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/processes-protected-by-exploit-security-policy.md): Application processes that run on your endpoint are protected by the exploit security policy.
- [File Integrity Monitoring (FIM)](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/file-integrity-monitoring-fim.md): Learn about File Integrity Monitoring (FIM) capabilities in Cortex Cloud.
- [CaaS Workloads](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/caas-workloads.md)
- [WildFire analysis concepts](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/wildfire-analysis-concepts.md): Learn about the analysis concepts used by Wildfire.
- [Guidelines for keeping Cortex XDR agents and content updated](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/guidelines-for-keeping-cortex-xdr-agents-and-content-updated.md): Learn more about how to control Cortex XDR agent and content upgrades.
- [About content updates](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/about-content-updates.md): To increase security coverage and quickly resolve any issues in policy, Palo Alto Networks can seamlessly deliver software packages called content updates.
- [Endpoint data collection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-protection/endpoint-data-collection.md): To aid in endpoint detection and issue investigation, the Cortex XDR agent collects endpoint information when an issue is generated.
- [Install and manage endpoints](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints.md): Learn how to set up profiles, policies and other settings for endpoint protection, how to install Cortex XDR agent on endpoints, and how to manage them after installation.
- [Set up endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection.md)
- [Set up endpoint profiles and exception rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules.md)
- [Set up malware prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-malware-prevention-profiles.md)
- [Set up exploit prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exploit-prevention-profiles.md)
- [Set up agent settings profiles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-agent-settings-profiles.md)
- [Set up restrictions prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-restrictions-prevention-profiles.md)
- [Set up exception profiles and rules](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules.md)
- [Exception configuration](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/exception-configuration.md)
- [Issue exclusions](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/issue-exclusions.md)
- [Add an issue exclusion rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/issue-exclusions/add-an-issue-exclusion-rule.md)
- [Add an IOC or BIOC rule exception](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-an-ioc-or-bioc-rule-exception.md)
- [Add a disable prevention rule for endpoints](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-disable-prevention-rule-for-endpoints.md)
- [Add a disable injection and prevention rule](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-disable-injection-and-prevention-rule.md)
- [Add a support exception rule for endpoints](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-support-exception-rule-for-endpoints.md)
- [Add a legacy exception rule for endpoints](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule-for-endpoints.md)
- [Add a new exceptions security profile](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule-for-endpoints/add-a-new-exceptions-security-profile.md)
- [Add a global endpoint policy exception](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule-for-endpoints/add-a-global-endpoint-policy-exception.md)
- [Set up Identity profiles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-identity-profiles.md)
- [Define endpoint groups](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/define-endpoint-groups.md)
- [Configure global agent settings](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/configure-global-agent-settings.md)
- [Apply profiles to endpoints](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/apply-profiles-to-endpoints.md)
- [Create an agent installation package](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/create-an-agent-installation-package.md)
- [Manage an agent installation package](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/create-an-agent-installation-package/manage-an-agent-installation-package.md)
- [Harden endpoint security](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/harden-endpoint-security.md)
- [Device control](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/device-control.md)
- [Host firewall](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/host-firewall.md)
- [Host firewall for Windows](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/host-firewall/host-firewall-for-windows.md)
- [Host firewall for macos](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/host-firewall/host-firewall-for-macos.md)
- [Disk encryption](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/disk-encryption.md)
- [Host Inventory](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/host-inventory.md)
- [Set a Cortex XDR agent Critical Environment version](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/harden-endpoint-security/set-a-cortex-xdr-agent-critical-environment-version.md)
- [Manage endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection.md)
- [Move agents between managing servers](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/move-agents-between-managing-servers.md)
- [Manage endpoint tags](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags.md)
- [Create an endpoint tag](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/create-an-endpoint-tag.md)
- [Remove an endpoint tag](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/remove-an-endpoint-tag.md)
- [Track your endpoint tags](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/track-your-endpoint-tags.md)
- [Permanently remove Endpoint tags from the system](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/permanently-remove-endpoint-tags-from-the-system.md)
- [Set an alias for an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags/set-an-alias-for-an-endpoint.md)
- [Manage endpoint prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-prevention-profiles.md)
- [Create a new prevention policy rule for serverless function](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/create-a-new-prevention-policy-rule-for-serverless-function.md)
- [View information about your endpoint prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/view-information-about-your-endpoint-prevention-profiles.md)
- [Upgrade Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/upgrade-cortex-xdr-agents.md)
- [Restart agent](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/restart-agent.md)
- [Uninstall the Cortex XDR agent](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/uninstall-the-cortex-xdr-agent.md)
- [Clear agent database](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/clear-agent-database.md)
- [Delete Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/delete-cortex-xdr-agents.md)
- [Manage agent tokens](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-agent-tokens.md)
- [Retrieve support file password](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/retrieve-support-file-password.md)
- [Send push notifications to iOS](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/send-push-notifications-to-ios.md)
- [Monitor agent operational status](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-operational-status.md)
- [Monitor agent activity](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-activity.md)
- [Monitor agent upgrade status](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-upgrade-status.md)
- [Endpoint DLP](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-dlp.md)
- [Cortex Data Loss Prevention (DLP) module overview](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-dlp/cortex-data-loss-prevention-dlp-module-overview.md): Learn about Cortex Data Loss Prevention (DLP) module, which provides a solution to prevent sensitive data exfiltration.
- [Archive file classification](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-dlp/cortex-data-loss-prevention-dlp-module-overview/archive-file-classification.md)
- [True-file type detection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-dlp/cortex-data-loss-prevention-dlp-module-overview/true-file-type-detection.md)
- [Personas workflow for DLP](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-dlp/personas-workflow-for-dlp.md): The data security administrator and data security viewer are responsible for identifying DLP requirements for creating data-in-motion rules and investigating issues and cases.
- [Best Practices](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-dlp/best-practices.md)
- [Configure DLP end-to-end](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-dlp/configure-dlp-end-to-end.md)
- [DLP status in all endpoints](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-dlp/dlp-status-in-all-endpoints.md)
- [Cortex DLP threat detection and issues](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security/endpoint-dlp/cortex-dlp-threat-detection-and-issues.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/endpoint-security.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
