> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exploit-prevention-profiles.md).

# Set up exploit prevention profiles

**Set up exploit prevention profiles**

Exploit prevention profiles block attempts to exploit system flaws in browsers, and in the operating system. For example, exploit prevention profiles help protect against exploit kits, illegal code execution, and other attempts to exploit process and system vulnerabilities.

You can configure the action that the Cortex XDR agent takes when attempts to exploit software vulnerabilities or flaws occur. To protect against specific exploit techniques, you can customize exploit protection capabilities in each exploit prevention profile. Default settings are shown in parentheses. To fine-tune your exploit prevention policy, you can override the configuration of each capability to block the malicious exploit, allow but report it, or disable the module.

To view which processes are protected by each capability, see Processes Protected by Exploit Security Policy.

For each setting that you override, clear the corresponding option to **Use Default**, and select the setting of your choice.

{% hint style="info" %}

### Note

In this profile, the **Report** options configure the endpoints to report the corresponding exploit attempts to Cortex XDR, without blocking them. The **Disabled** options configure the endpoints to neither analyze nor report the corresponding malware or behavior.
{% endhint %}

The tasks below are organized according to the operating systems used by your organization's endpoints.

<details>

<summary>Windows</summary>

1. Add a new profile and define basic settings.
   1. From Cortex XDR, select **Inventory** → **Endpoints** → **Policy Management** → **Prevention** → **Profiles**. Click **+Add Profile**, and select whether to create a new profile, or to import a profile from a file.

      <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>New profiles based on imported profiles are added, and do not replace existing ones.</p></div>
   2. Select the **Windows** platform, and **Exploit** as the profile type.
   3. Click **Next**.
   4. For **Profile Name**, enter a unique name for the profile. The name can contain only letters, numbers, or spaces, and must be no more than 30 characters. The name will be visible from the list of profiles when you configure a policy rule.
   5. For **Description**, to provide additional context for the purpose or business reason for creating the profile, enter a profile **description**. For example, you might include a case identification number or a link to a help desk ticket.
2. Configure **Browser Exploits Protection**, to protect endpoints from malicious or compromised websites.

   | Item        | Options                                                 | More details                                                                                                                       |
   | ----------- | ------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- |
   | Action Mode | <ul><li>Block</li><li>Report</li><li>Disabled</li></ul> | When the Cortex XDR agent detects attempts to exploit browser processes for malicious purposes, it performs the configured action. |
3. Configure **Logical Exploits Protection** to prevent execution of malicious code using common operating system mechanisms.

   | Item            | Options                                                 | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
   | --------------- | ------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
   | Action Mode     | <ul><li>Block</li><li>Report</li><li>Disabled</li></ul> | When the Cortex XDR agent detects attempts to execute malicious code using operating system mechanisms, it performs the configured action.                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
   | Block List DLLs |                                                         | <p>The block list blocks the specified DLLs when they are run by a protected process, using the DLL Hijacking module.</p><p>1. Click <strong>+Add</strong> to configure entries in your <strong>Block List</strong>.</p><p>2. Enter the name of the process that you want to block.</p><p>3. Enter the associated DLL name.</p><p>The DLL folder or file must include the complete path. To complete the path, you can use environment variables or the asterisk (<em>) as a wildcard to match any string of characters (for example,</em> <strong><code>/windows32/</code></strong>).</p> |
4. Configure **Known Vulnerable Processes Protection** to automatically protect endpoints from attacks that try to leverage common operating system mechanisms for malicious purposes.

   | Item                            | Options                                                 | More details                                                                                                                                                                                                             |
   | ------------------------------- | ------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
   | Action Mode                     | <ul><li>Block</li><li>Report</li><li>Disabled</li></ul> | Attackers can use existing mechanisms in the operating system to execute malicious code. When you set this option to **Block**, in order to block such code, you can also configure **Java Deserialization Protection**. |
   | Java Deserialization Protection | <ul><li>Enabled</li><li>Disabled</li></ul>              | When enabled, the same action mode defined for the **Known Vulnerable Process Protection** is inherited here.                                                                                                            |
5. Configure **Operating System Exploit Protection** to prevent attackers from using operating system mechanisms for malicious purposes.

   | Item        | Options                                                 | More details                                                                                                                                                       |
   | ----------- | ------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
   | Action Mode | <ul><li>Block</li><li>Report</li><li>Disabled</li></ul> | When the Cortex XDR agent detects attempts to use the operating system's own mechanisms to perform an attack, the Cortex XDR agent performs the configured action. |
6. Configure **Exploit Protection for Additional Processes** to protect third-party processes running on endpoints.

   | Item        | Options                                                 | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
   | ----------- | ------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
   | Action Mode | <ul><li>Block</li><li>Report</li><li>Disabled</li></ul> | <p>The Cortex XDR agent can protect third-party processes from exploitation. To protect these processes, define them in the <strong>Processes</strong> list below this field. If you select the <strong>Block</strong> option, we recommend that you perform testing and validation to ensure that there are no compatibility issues with the third-party processes that you have defined.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>In exploit prevention profiles, if you change the action mode for processes, you must restart the protected processes for the following security modules to take effect on the process and its forked processes:</p><ul><li>Brute Force Protection</li><li>Java Deserialization</li><li>ROP</li><li>SO Hijacking</li></ul></div> |
   | Processes   |                                                         | <p>If you want to add exploit protection for one or more additional third-party processes, add them here.</p><p>1. Click <strong>+Add</strong> to configure entries in your <strong>Processes</strong> list.</p><p>2. Enter the file name of the process that you want to block, and press ENTER.</p><p>3. For additional processes, repeat the previous steps.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
7. Configure **Unpatched Vulnerabilities Protection** to provide a temporary workaround for protecting unpatched endpoints from known vulnerabilities.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>This step provides a temporary workaround for the following publicly known information-security vulnerabilities and exposures: CVE-2021-24074, CVE-2021-24086 and CVE-2021-24094.</p></div>

   If you choose not to patch the endpoint, the **Unpatched Vulnerabilities Protection** capability allows the Cortex XDR agent to apply a workaround to protect the endpoints from the known vulnerability. It takes the Cortex XDR agent up to 6 hours to enforce your configured policy on the endpoints.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>If you have Windows endpoints in your network that are unpatched and exposed to a known vulnerability, we strongly recommend that you upgrade to the latest Windows Update that has a fix for that vulnerability.</p></div>

   | Item                          | Options                                                                                                                                                        | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
   | ----------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Modify IPv4 and IPv6 Settings | <ul><li>Do not modify system settings</li><li>Modify settings until the endpoint is patched</li><li>Revert system settings to your previous settings</li></ul> | <p>To address known vulnerabilities <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-24074">CVE-2021-24074</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-24086">CVE-2021-24086</a>, and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-24094">CVE-2021-24094</a>, you can <strong>Modify IPv4 and IPv6 settings</strong> as follows:</p><ul><li><strong>Do not modify system settings</strong> (default): Do not modify the IPv4 and IPv6 settings currently set on the endpoint, whether the current values are your original values or values that were modified as part of this workaround.</li><li><p><strong>Modify system settings until the endpoint is patched</strong>: If the endpoint is already patched, this option does not modify any system settings. For unpatched endpoints, the Cortex XDR agent runs the following commands to temporarily modify the IPv4 and IPv6 settings until the endpoint is patched. After the endpoint is patched for <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-24074">CVE-2021-24074</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-24086">CVE-2021-24086</a>, and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-24094">CVE-2021-24094</a>, all modified Windows system settings as part of this workaround are automatically reverted to their values before modification. Palo Alto Networks strongly recommends that you review these commands before applying this workaround in your network to ensure your critical business components are not affected or harmed:</p><p><code>netsh int ipv6 set global reassemblylimit=0</code></p><p>This command disables IPv6 fragmentation on the endpoint.</p><p><code>netsh int ipv4 set global sourceroutingbehavior=drop</code></p><p>This command disables LSR / loose source routing for IPv4.</p></li><li><strong>Revert system settings to your previous settings</strong>: Revert all Windows system settings to their values before modification as part of this workaround, regardless of whether the endpoint was patched or not.</li></ul><div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Warning</strong></p><p>This workaround applies only to the specific <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-24086">Windows versions listed as exposed to these CVEs</a>, and requires a Cortex XDR agent release 7.1 or later and content 167-51646 or later. This workaround is not recommended for non-persistent, stateless, or linked-clone environments. In some cases, enabling this workaround can affect the network functionality on the endpoint.</p></div> |
8. To save the profile, click **Create**.

What to do next

If you are ready to apply your new profile to endpoints, you do this by adding it to a policy rule. If you still need to define other profiles, you can do this later. During policy rule creation or editing, you select the endpoints to which to assign the policy. There are different ways of doing this, such as:

</details>

<details>

<summary>macOS</summary>

1. Add a new profile and define basic settings.
   1. From Cortex XDR, select **Inventory** → **Endpoints** → **Policy Management** → **Prevention** → **Profiles**. Click **+Add Profile**, and select whether to create a new profile, or to import a profile from a file.

      <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>New profiles based on imported profiles are added, and do not replace existing ones.</p></div>
   2. Select the **macOS** platform, and **Exploit** as the profile type.
   3. Click **Next**.
   4. Enter a unique **Profile Name** for the profile. The name can contain only letters, numbers, or spaces, and must be no more than 30 characters. The name will be visible from the list of profiles when you configure a policy rule.
   5. For **Description**, to provide additional context for the purpose or business reason for creating the profile, enter a profile **description**. For example, you might include a case identification number or a link to a help desk ticket.
2. Configure **Browser Exploits Protection**, to protect endpoints from malicious or compromised websites.

   | Item        | Options                                                 | More details                                                                                                                       |
   | ----------- | ------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- |
   | Action Mode | <ul><li>Block</li><li>Report</li><li>Disabled</li></ul> | When the Cortex XDR agent detects attempts to exploit browser processes for malicious purposes, it performs the configured action. |
3. Configure **Logical Exploits Protection** to prevent execution of malicious code using common operating system mechanisms.

   | Item        | Options                                                 | More details                                                                                                                               |
   | ----------- | ------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ |
   | Action Mode | <ul><li>Block</li><li>Report</li><li>Disabled</li></ul> | When the Cortex XDR agent detects attempts to execute malicious code using operating system mechanisms, it performs the configured action. |
4. Configure **Known Vulnerable Processes Protection** to automatically protect endpoints from attacks that try to leverage common operating system mechanisms for malicious purposes.

   | Item        | Options                                                 | More details                                                                                                                                                                                                             |
   | ----------- | ------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
   | Action Mode | <ul><li>Block</li><li>Report</li><li>Disabled</li></ul> | Attackers can use existing mechanisms in the operating system to execute malicious code. When you set this option to **Block**, in order to block such code, you can also configure **Java Deserialization Protection**. |
5. Configure **Operating System Exploit Protection** to prevent attackers from using operating system mechanisms for malicious purposes.

   | Item        | Options                                                 | More details                                                                                                                                                       |
   | ----------- | ------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
   | Action Mode | <ul><li>Block</li><li>Report</li><li>Disabled</li></ul> | When the Cortex XDR agent detects attempts to use the operating system's own mechanisms to perform an attack, the Cortex XDR agent performs the configured action. |
6. Configure **Exploit Protection for Additional Processes** to protect third-party processes running on endpoints.

   | Item        | Options                                                 | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
   | ----------- | ------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
   | Action Mode | <ul><li>Block</li><li>Report</li><li>Disabled</li></ul> | <p>The Cortex XDR agent can protect third-party processes from exploitation. To protect these processes, define them in the <strong>Processes</strong> list below this field. If you select the <strong>Block</strong> option, we recommend that you perform testing and validation to ensure that there are no compatibility issues with the third-party processes that you have defined.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>In exploit prevention profiles, if you change the action mode for processes, you must restart the protected processes for the following security modules to take effect on the process and its forked processes:</p><ul><li>Brute Force Protection</li><li>Java Deserialization</li><li>ROP</li><li>SO Hijacking</li></ul></div> |
   | Processes   |                                                         | <p>If you want to add exploit protection for one or more additional third-party processes, add them here.</p><p>1. Click <strong>+Add</strong> to configure entries in your <strong>Processes</strong> list.</p><p>2. Enter the file name of the process that you want to block, and press ENTER.</p><p>3. For additional processes, repeat the previous steps.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
7. Configure **Kernel Privilege Escalation Protection** to identify and neutralize privilege escalation. Supported on Cortex XDR agent 9.2 and later.

   | Item                       | Options                                                        | More details                                                                                                                                                      |
   | -------------------------- | -------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Action mode                | <p></p><ul><li>Block</li><li>Report</li><li>Disabled</li></ul> | Risky Profile Status: Setting the action to Block is the recommended security posture. If you set Report or Disabled, the platform may flag the profile as Risky. |
   | Quarantine Malicious Files | <p></p><ul><li>Enabled</li><li>Disabled</li></ul>              |                                                                                                                                                                   |
8. To save the profile, click **Create**.

What to do next

If you are ready to apply your new profile to endpoints, you do this by adding it to a policy rule. If you still need to define other profiles, you can do this later. During policy rule creation or editing, you select the endpoints to which to assign the policy. There are different ways of doing this, such as:

</details>

<details>

<summary>Linux</summary>

1. Add a new profile and define basic settings.
   1. From Cortex XDR, select **Inventory** → **Endpoints** → **Policy Management** → **Prevention** → **Profiles**. Click **+Add Profile**, and select whether to create a new profile, or to import a profile from a file.

      <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>New profiles based on imported profiles are added, and do not replace existing ones.</p></div>
   2. Select the **Linux** platform, and **Exploit** as the profile type.
   3. Click **Next**.
   4. Enter a unique **Profile Name** for the profile. The name can contain only letters, numbers, or spaces, and must be no more than 30 characters. The name will be visible from the list of profiles when you configure a policy rule.
   5. For **Description**, to provide additional context for the purpose or business reason for creating the profile, enter a profile **description**. For example, you might include a case identification number or a link to a help desk ticket.
2. Configure **Known Vulnerable Processes Protection** to automatically protect endpoints from attacks that try to leverage common operating system mechanisms for malicious purposes.

   | Item        | Options                                                 | More details                                                                                                                                                                                                             |
   | ----------- | ------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
   | Action Mode | <ul><li>Block</li><li>Report</li><li>Disabled</li></ul> | Attackers can use existing mechanisms in the operating system to execute malicious code. When you set this option to **Block**, in order to block such code, you can also configure **Java Deserialization Protection**. |
3. Configure **Operating System Exploit Protection** to prevent attackers from using operating system mechanisms for malicious purposes.

   | Item        | Options                                                 | More details                                                                                                                                                       |
   | ----------- | ------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
   | Action Mode | <ul><li>Block</li><li>Report</li><li>Disabled</li></ul> | When the Cortex XDR agent detects attempts to use the operating system's own mechanisms to perform an attack, the Cortex XDR agent performs the configured action. |
4. Configure **Exploit Protection for Additional Processes** to protect third-party processes running on endpoints.

   | Item        | Options                                                 | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
   | ----------- | ------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
   | Action Mode | <ul><li>Block</li><li>Report</li><li>Disabled</li></ul> | <p>The Cortex XDR agent can protect third-party processes from exploitation. To protect these processes, define them in the <strong>Processes</strong> list below this field. If you select the <strong>Block</strong> option, we recommend that you perform testing and validation to ensure that there are no compatibility issues with the third-party processes that you have defined.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>In exploit prevention profiles, if you change the action mode for processes, you must restart the protected processes for the following security modules to take effect on the process and its forked processes:</p><ul><li>Brute Force Protection</li><li>Java Deserialization</li><li>ROP</li><li>SO Hijacking</li></ul></div> |
   | Processes   |                                                         | <p>If you want to add exploit protection for one or more additional third-party processes, add them here.</p><p>1. Click <strong>+Add</strong> to configure entries in your <strong>Processes</strong> list.</p><p>2. Enter the file name of the process that you want to block, and press ENTER.</p><p>3. For additional processes, repeat the previous steps.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
5. To save the profile, click **Create**.

What to do next

If you are ready to apply your new profile to endpoints, you do this by adding it to a policy rule. If you still need to define other profiles, you can do this later. During policy rule creation or editing, you select the endpoints to which to assign the policy. There are different ways of doing this, such as:

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exploit-prevention-profiles.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
