> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-protection/endpoint-protection-capabilities.md).

# Endpoint protection capabilities

**Endpoint protection capabilities**

Each security profile provides a tailored list of protection capabilities that you can configure for the platform you select. The following table describes the protection capabilities you can customize in a security profile. The table also indicates which platforms support the protection capability (a dash (—) indicates the capability is not supported).

| Protection capability                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | Windows                                        | Mac                                            | Linux                                          | Android                                        | iOS                                            |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------- | ---------------------------------------------- | ---------------------------------------------- | ---------------------------------------------- | ---------------------------------------------- |
| Agent security profiles                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |                                                |                                                |                                                |                                                |                                                |
| <p><strong>Agentic Endpoint Security (AES)</strong><br>AI agents, AI coding tools, MCP servers, IDE extensions, browser plugins, and code packages such as npm and pip create a non-binary endpoint attack surface that traditional antivirus tools do not cover. By enabling this capability, the Cortex XDR agent discovers agentic software running on the endpoint and remediates risks based on your AES policy. Learn more about <a href="https://docs.koi.ai/">Agentic Endpoint Security with Koi</a>.</p> | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| Exploit security profiles                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |                                                |                                                |                                                |                                                |                                                |
| <p><strong>Browser exploits protection</strong></p><p>Browsers can be subject to exploitation attempts from malicious web pages and exploit kits that are embedded in compromised websites. By enabling this capability, the Cortex XDR agent automatically protects browsers from common exploitation attempts.</p>                                                                                                                                                                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>Logical exploits protection</strong></p><p>Attackers can use existing mechanisms in the operating system—such as DLL-loading processes or built in system processes—to execute malicious code. By enabling this capability, the Cortex XDR agent automatically protects endpoints from attacks that try to leverage common operating system mechanisms for malicious purposes.</p>                                                                                                                     | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>Known vulnerable processes protection</strong></p><p>Common applications in the operating system, such as PDF readers, Office applications, and even processes that are a part of the operating system itself can contain bugs and vulnerabilities that an attacker can exploit. By enabling this capability, the Cortex XDR agent protects these processes from attacks which try to exploit known process vulnerabilities.</p>                                                                       | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>Exploit protection for additional processes</strong></p><p>To extend protection to third-party processes that are not protected by the default policy from exploitation attempts, you can add additional processes to this capability.</p>                                                                                                                                                                                                                                                             | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>Operating system exploit protection</strong></p><p>Attackers commonly leverage the operating system itself to accomplish a malicious action. By enabling this capability, the Cortex XDR agent protects operating system mechanisms such as privilege escalation and prevents them from being used for malicious purposes.</p>                                                                                                                                                                         | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>Unpatched vulnerabilities protection</strong></p><p>If you have Windows endpoints in your network that are unpatched and exposed to a known vulnerability, Palo Alto Networks strongly recommends that you upgrade to the latest Windows Update that has a fix for that vulnerability. If you choose not to patch the endpoint, the Unpatched Vulnerabilities Protection capability allows the Cortex XDR agent to apply a workaround to protect the endpoints from the known vulnerability.</p>       | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              | —                                              |
| Malware security profiles                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |                                                |                                                |                                                |                                                |                                                |
| <p><strong>Behavioral threat protection</strong></p><p>Prevents sophisticated attacks that leverage built-in OS executables and common administration utilities by continuously monitoring endpoint activity for malicious causality chains.</p>                                                                                                                                                                                                                                                                  | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>Credential gathering protection</strong></p><p>Targets attempts to access and harvest passwords and credentials.</p>                                                                                                                                                                                                                                                                                                                                                                                   | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>Anti webshell protection</strong></p><p>Prevents web shell attacks by continuously monitoring endpoints for processes that try to drop malicious files.</p>                                                                                                                                                                                                                                                                                                                                            | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>Financial malware threat protection</strong></p><p>Targets attempts to access or steal financial or banking information.</p>                                                                                                                                                                                                                                                                                                                                                                           | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>Cryptominers protection</strong></p><p>Prevents cryptomining by monitoring for processes which attempt to locate or steal cryptocurrencies.</p>                                                                                                                                                                                                                                                                                                                                                        | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>In-process shellcode protection</strong></p><p>Targets attempts to run in-process shellcodes that load malicious code.</p>                                                                                                                                                                                                                                                                                                                                                                             | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              | —                                              |
| <p><strong>Ransomware protection</strong></p><p>Targets encryption based activity associated with ransomware to analyze and halt ransomware before any data loss occurs.</p>                                                                                                                                                                                                                                                                                                                                      | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>Prevent malicious child process execution</strong></p><p>Prevents script-based attacks used to deliver malware by blocking known targeted processes from launching child processes commonly used to bypass traditional security approaches.</p>                                                                                                                                                                                                                                                        | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>Portable executables and DLLs examination</strong></p><p>Analyzes and prevents malicious executable and DLL files from running.</p>                                                                                                                                                                                                                                                                                                                                                                    | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>ELF files examination</strong></p><p>Analyzes and prevents malicious ELF files from being executed or written to disk.</p>                                                                                                                                                                                                                                                                                                                                                                             | —                                              | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>Local file threat examination</strong></p><p>Analyzes and quarantines malicious PHP files arriving from the web server.</p>                                                                                                                                                                                                                                                                                                                                                                            | —                                              | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>Office files examination</strong></p><p>Analyzes and prevents malicious macros embedded in Microsoft Office files from running.</p>                                                                                                                                                                                                                                                                                                                                                                    | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              | —                                              |
| <p><strong>JScript files examination</strong></p><p>Analyzes and prevent malicious JScript files from being executed or written to disk.</p>                                                                                                                                                                                                                                                                                                                                                                      | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              | —                                              |
| <p><strong>Mach-O files examination</strong></p><p>Analyzes and prevents malicious mach-o files from loading and running.</p>                                                                                                                                                                                                                                                                                                                                                                                     | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>DMG files examination</strong></p><p>Analyzes and prevents malicious DMG files from running.</p>                                                                                                                                                                                                                                                                                                                                                                                                       | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>APK files examination</strong></p><p>Analyzes and prevents malicious APK files from running.</p>                                                                                                                                                                                                                                                                                                                                                                                                       | —                                              | —                                              | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              |
| <p><strong>Reverse shell protection</strong></p><p>Detects suspicious or abnormal network activity from shell processes and terminate the malicious shell process.</p>                                                                                                                                                                                                                                                                                                                                            | —                                              | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>Network packet inspection engine</strong></p><p>Analyzes network packet data to detect malicious behavior.</p>                                                                                                                                                                                                                                                                                                                                                                                         | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>Dynamic kernel protection</strong></p><p>Protect the endpoint from kernel-level threats such as bootkits, rootkits, and susceptible drivers.</p>                                                                                                                                                                                                                                                                                                                                                       | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              | —                                              |
| <p><strong>SMS and MMS malicious URL filtering</strong></p><p>Filter, report, or block (iOS only) malicious URLs received in SMS/MMS messages.</p>                                                                                                                                                                                                                                                                                                                                                                | —                                              | —                                              | —                                              | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) |
| **Spam reports**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | —                                              | —                                              | —                                              | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) |
| **Call and messages blocking**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | —                                              | —                                              | —                                              | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) |
| **Container-escaping attempts**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | —                                              | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>Network URL filtering</strong></p><p>URL filtering for supervised devices</p>                                                                                                                                                                                                                                                                                                                                                                                                                          | —                                              | —                                              | —                                              | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) |
| <p><strong>Cryptocurrency wallets protection</strong></p><p>Protection for cryptocurrency wallets stored on endpoints.</p>                                                                                                                                                                                                                                                                                                                                                                                        | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>LDAP query protection</strong></p><p>Analyze and act upon suspicious LDAP queries sent by the agent to a Domain Controller, to detect and block Active Directory reconnaissance attacks.</p>                                                                                                                                                                                                                                                                                                           | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              | —                                              |
| <p><strong>Malicious device protection</strong></p><p>Protect your systems from unauthorized hardware attacks and malicious USB devices. The Malicious Device Prevention module identifies and blocks Human Interface Device (HID) tools, such as the "USB Rubber Ducky", that exploit device trust to inject unauthorized keystrokes and similar actions. This feature reduces the physical attack surface, and prevents hardware-based social engineering threats from compromising data.</p>                   | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| Restrictions security profiles                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |                                                |                                                |                                                |                                                |                                                |
| <p><strong>Execution paths</strong></p><p>Many attack scenarios are based on writing malicious executable files to certain folders such as the local temp or download folder and then running them. Use this capability to restrict the locations from which executable files can run.</p>                                                                                                                                                                                                                        | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              | —                                              |
| <p><strong>Network locations</strong></p><p>To prevent attack scenarios that are based on writing malicious files to remote folders, you can restrict access to all network locations except for those that you explicitly trust.</p>                                                                                                                                                                                                                                                                             | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              | —                                              |
| <p><strong>Removable media</strong></p><p>To prevent malicious code from gaining access to endpoints using external media such as a removable drive, you can restrict the executable files, that users can launch from external drives attached to the endpoints in your network.</p>                                                                                                                                                                                                                             | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              | —                                              |
| <p><strong>Optical drive</strong></p><p>To prevent malicious code from gaining access to endpoints using optical disc drives (CD, DVD, and Blu-ray), you can restrict the executable files, that users can launch from optical disc drives connected to the endpoints in your network.</p>                                                                                                                                                                                                                        | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              | —                                              |
|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |                                                |                                                |                                                |                                                |                                                |
|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |                                                |                                                |                                                |                                                |                                                |

**Endpoint protection modules**

Each security profile applies multiple security modules to protect your endpoints from a wide range of attack techniques. While the settings for each security module are not configurable, the Cortex XDR agent activates a specific protection module depending on the type of attack, the configuration of your security policy, and the operating system of the endpoint.

When a security event occurs, the Cortex XDR agent logs details about the event including the security module employed by the Cortex XDR agent to detect and prevent the attack based on the technique. To help you understand the nature of the attack, the alert identifies the protection module the Cortex XDR agent employed.

The following table lists the modules and the platforms on which they are supported. A dash (—) indicates that the module is not supported.

| Module                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | Windows                                        | Mac                                            | Linux                                          | Android                                        |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------- | ---------------------------------------------- | ---------------------------------------------- | ---------------------------------------------- |
| <p><strong>Anti-Ransomware</strong></p><p>Targets encryption-based activity associated with ransomware and have the ability to analyze and halt ransomware activity before any data loss occurs.</p>                                                                                                                                                                                                                                                                                                                       | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>APC protection</strong></p><p>Prevents attacks that change the execution order of a process by redirecting an asynchronous procedure call (APC) to point to the malicious shellcode.</p>                                                                                                                                                                                                                                                                                                                        | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>Behavioral threat</strong></p><p>Prevents sophisticated attacks that leverage built-in OS executables and common administration utilities by continuously monitoring endpoint activity for malicious causality chains.</p>                                                                                                                                                                                                                                                                                      | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              |
| <p><strong>Brute force protection</strong></p><p>Prevents attackers from hijacking the process control flow by monitoring memory layout enumeration attempts.</p>                                                                                                                                                                                                                                                                                                                                                          | —                                              | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              |
| <p><strong>Child process protection</strong></p><p>Prevents script-based attacks that are used to deliver malware, such as ransomware, by blocking known targeted processes from launching child processes that are commonly used to bypass traditional security approaches.</p>                                                                                                                                                                                                                                           | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              |
| <p><strong>Container escaping protection</strong></p><p>Prevents container-escaping attempts</p>                                                                                                                                                                                                                                                                                                                                                                                                                           | —                                              | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              |
| <p><strong>CPL protection</strong></p><p>Protects against vulnerabilities related to the display routine for Windows Control Panel Library (CPL) shortcut images, which can be used as a malware infection vector.</p>                                                                                                                                                                                                                                                                                                     | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>Data Execution Prevention (DEP)</strong></p><p>Prevents areas of memory defined to contain only data from running executable code.</p>                                                                                                                                                                                                                                                                                                                                                                          | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>DLL hijacking</strong></p><p>Prevents DLL-hijacking attacks where the attacker attempts to load dynamic-link libraries on Windows operating systems from unsecured locations to gain control of a process.</p>                                                                                                                                                                                                                                                                                                  | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>DLL security</strong></p><p>Prevents access to crucial DLL metadata from untrusted code locations.</p>                                                                                                                                                                                                                                                                                                                                                                                                          | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>Dylib hijacking</strong></p><p>Prevents Dylib-hijacking attacks where the attacker attempts to load dynamic libraries on Mac operating systems from unsecured locations to gain control of a process.</p>                                                                                                                                                                                                                                                                                                       | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>Exploit kit fingerprint</strong></p><p>Protects against the fingerprinting technique used by browser exploit kits to identify information: such as the OS or applications which run on an endpoint—that attackers can leverage when launching an attack to evade protection capabilities.</p>                                                                                                                                                                                                                   | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>Font protection</strong></p><p>Prevents improper font handling, a common target of exploits.</p>                                                                                                                                                                                                                                                                                                                                                                                                                | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>Gatekeeper enhancement</strong></p><p>Enhances the macOS gatekeeper functionality that allows apps to run based on their digital signature. This module provides an additional layer of protection by extending gatekeeper functionality to bundles and child processes so you can enforce the signature level of your choice.</p>                                                                                                                                                                              | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>Hash exception</strong></p><p>Halts execution of files that an administrator identified as malware regardless of the WildFire verdict.</p>                                                                                                                                                                                                                                                                                                                                                                      | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) |
| <p><strong>Hot patch protection</strong></p><p>Prevents the use of system functions to bypass DEP and address space layout randomization (ASLR).</p>                                                                                                                                                                                                                                                                                                                                                                       | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>Java deserialization</strong></p><p>Blocks attempts to execute malicious code during the Java objects deserialization process on Java-based servers.</p>                                                                                                                                                                                                                                                                                                                                                        | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              |
| <p><strong>JIT</strong></p><p>Prevents an attacker from bypassing the operating system's memory mitigations using just-in-time (JIT) compilation engines.</p>                                                                                                                                                                                                                                                                                                                                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>Kernel Integrity Monitor (KIM)</strong></p><p>Prevents rootkit and vulnerability exploitation on Linux endpoints. On the first detection of suspicious rootkit behavior, the behavioral threat protection (BTP) module generates a Cortex XDR Agent alert. Cortex XDR stitches logs about the process that loaded the kernel module with other logs relating to the kernel module to aid in the alert investigation. When the Cortex XDR agent detects subsequent rootkit behavior, it blocks the activity.</p> | —                                              | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              |
| <p><strong>LDAP query protection</strong></p><p>Analyzes and acts upon suspicious LDAP queries received by the Domain Controller, to detect and block Active Directory reconnaissance attacks.</p>                                                                                                                                                                                                                                                                                                                         | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>Local analysis</strong></p><p>Examines hundreds of characteristics of an unknown executable file, DLL, or macro to determine if it is likely to be malware. The local analysis module uses a static set of pattern-matching rules that inspect multiple file features and attributes, and a statistical model that was developed using machine learning on WildFire threat intelligence.</p>                                                                                                                    | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              |
| <p><strong>Local Threat Evaluation Engine (LTEE)</strong></p><p>Protects against malicious PHP files arriving from the web server.</p>                                                                                                                                                                                                                                                                                                                                                                                     | —                                              | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              |
| <p><strong>Local privilege escalation protection</strong></p><p>Prevents attackers from performing malicious activities that require privileges that are higher than those assigned to the attacked or malicious process.</p>                                                                                                                                                                                                                                                                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              |
| <p><strong>Malicious device protection</strong></p><p>Protects your systems from unauthorized hardware attacks and malicious Human Interface Devices (HIDs) such as malicious USB devices.</p>                                                                                                                                                                                                                                                                                                                             | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>Master Boot Record (MBR) Model</strong></p><p>Protects against malicious Master Boot Record (MBR) manipulations.</p>                                                                                                                                                                                                                                                                                                                                                                                            | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>Network packet inspection engine</strong></p><p>Analyze network packet data to detect malicious behavior already at the network level. The engine leverages both Palo Alto Networks NGFW content rules, and new Cortex XDR content rules created by the Research Team which are updated through the security content.</p>                                                                                                                                                                                       | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              |
| <p><strong>Null dereference</strong></p><p>Prevents malicious code from mapping to address zero in the memory space, making null dereference vulnerabilities unexploitable.</p>                                                                                                                                                                                                                                                                                                                                            | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>Restricted execution - local path</strong></p><p>Prevents unauthorized execution from a local path.</p>                                                                                                                                                                                                                                                                                                                                                                                                         | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>Restricted execution - network location</strong></p><p>Prevents unauthorized execution from a network path.</p>                                                                                                                                                                                                                                                                                                                                                                                                 | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>Restricted execution - removable media</strong></p><p>Prevents unauthorized execution from removable media.</p>                                                                                                                                                                                                                                                                                                                                                                                                 | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>Reverse shell protection</strong></p><p>Blocks malicious activity where an attacker redirects standard input and output streams to network sockets.</p>                                                                                                                                                                                                                                                                                                                                                         | —                                              | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              |
| <p><strong>ROP</strong></p><p>Protects against the use of return-oriented programming (ROP) by protecting APIs used in ROP chains.</p>                                                                                                                                                                                                                                                                                                                                                                                     | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              |
| <p><strong>SEH</strong></p><p>Prevents hijacking of the structured exception handler (SEH), a commonly exploited control structure that can contain multiple SEH blocks that form a linked list chain, which contains a sequence of function records.</p>                                                                                                                                                                                                                                                                  | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>Shellcode protection</strong></p><p>Reserves and protects certain areas of memory commonly used to house payloads using heap spray techniques.</p>                                                                                                                                                                                                                                                                                                                                                              | —                                              | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              |
| <p><strong>ShellLink</strong></p><p>Prevents shell-link logical vulnerabilities.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                       | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>SO hijacking protection</strong></p><p>Prevents dynamic loading of libraries from unsecured locations to gain control of a process.</p>                                                                                                                                                                                                                                                                                                                                                                         | —                                              | —                                              | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              |
| <p><strong>SysExit</strong></p><p>Prevents using system calls to bypass other protection capabilities.</p>                                                                                                                                                                                                                                                                                                                                                                                                                 | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>UASLR</strong></p><p>Improves or altogether implements ASLR (address space layout randomization) with greater entropy, robustness, and strict enforcement.</p>                                                                                                                                                                                                                                                                                                                                                  | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>UEFI BTP</strong></p><p>Reinforces the malware protection from pre-boot attacks.</p>                                                                                                                                                                                                                                                                                                                                                                                                                            | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>Vulnerable drivers protection</strong></p><p>Detect attempts to load vulnerable drivers.</p>                                                                                                                                                                                                                                                                                                                                                                                                                    | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | —                                              | —                                              | —                                              |
| <p><strong>WildFire</strong></p><p>Leverages WildFire for threat intelligence to determine whether a file is malware. In the case of unknown files, Cortex XDR can forward samples to WildFire for in-depth analysis.</p>                                                                                                                                                                                                                                                                                                  | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) |
| <p><strong>WildFire post-detection (malware and grayware)</strong></p><p>Identifies a file that was previously allowed to run on an endpoint that is now determined to be malware. Post-detection events provide notifications for each endpoint on which the file is executed.</p>                                                                                                                                                                                                                                        | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) | ![check-mark.png](/files/Gi3T4hhyLshxDdoPfuVY) |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/endpoint-protection/endpoint-protection-capabilities.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
