For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex Cloud Runtime

Add a new exceptions security profile

You can configure exceptions that apply to specific groups of endpoints or you can add a global endpoint policy exception.

How to create an endpoint-specific exception

  1. Add a new profile.

    1. From Cortex Cloud, select InventoryEndpointsPolicy ManagementPreventionProfiles+Add Profile and select whether to Create New or Import from File a new profile.

      Note

      New imported profiles are added and not replaced.

    2. Select the platform to which the profile applies and Exceptions as the profile type.

    3. Click Next.

  2. Define the basic settings.

    1. Select a unique Profile Name to identify the profile. The name can contain only letters, numbers, or spaces, and must be no more than 30 characters. The name will be visible from the list of profiles when you configure a policy rule.

    2. To provide additional context for the purpose or business reason for creating the profile, specify a profile Description. For example, you might include a case identification number or a link to a help desk ticket.

  3. Configure the exceptions profile.

Configure a process exception
  1. Select the operating system.

  2. Enter the process name.

  3. Select the endpoint protection modules that allow the process to run.

    • Select All to apply the exception across all security modules.

    • Select Disable Injection to apply the exception across these exploit modules: APC Guard, CPL Execution Protection, DEP, DLL Hijacking Protection, DLL Security, EPM D02, Exception Heap Spray Check, Exception SysExist Check, Exploit Kit Fingerprinting Protection, Font Protection, Hot Patch Protection, JIT Mitigation, Library Preallocation, Memory Limit Heap Spray Check, Null Dereference Protection, Password Theft Protection, ROP Mitigation, SEH Protection, Shellcode Preallocation, and UASLR.

  4. Click the adjacent arrow.

  5. After adding all processes, select Create.

You can later edit these settings from the Process Execution profile.

Configure a support exception
  1. Import the JSON file from Palo Alto Networks Support. Browse for it or drag it onto the page.

  2. Click Create.

Configure module-specific exceptions for the selected profile platform
  • Behavioral Threat Protection Rule Exception: Right-click a Behavioral Threat alert and select Create alert exception. Review the platform and rule name. Select CGO hash, CGO signer, CGO process path, or CGO command arguments as needed. Select Profile from Exception Scope, then click Create.

  • Digital Signer Exception: Right-click a Digital Signer Restriction issue and select Create issue exception. Set Exception Scope to Profile, select the exception profile name, then click Add.

  • Java Deserialization Exception: Right-click a benign Suspicious Input Deserialization issue and select Create issue exception. Set Exception Scope to Profile, select the exception profile name, then click Add.

  • Local File Threat Examination Exception: Right-click a PHP file issue and select Create issue exception. Set Exception Scope to Profile, select the exception profile name, then click Add.

  • Gatekeeper Enhancement Exception: Right-click the issue and select Create issue exception. Set Exception Scope to Profile, select the exception profile name, then click Add. This keeps enforcement active for other child processes.

At any point, click the Generating Issue ID to return to the issue that generated the exception. You cannot edit module-specific exceptions.

  1. Apply profiles to endpoints.

    To remove an exceptions profile, go to the Profiles page, right-click the profile, then select Delete.

Last updated

Was this helpful?