For the complete documentation index, see llms.txt. This page is also available as Markdown.

Add a Malware Prevention Profile (Administrator Task)

From the Cortex XDR or XSIAM tenant, you can configure the action that Cortex XDR agents on iOS devices take for known malicious URLs and spam numbers. You can also configure granular control and moni

You can use Malware prevention profiles to configure the actions that Cortex XDR agents take when they detect known malicious URLs or spam numbers. You can also configure granular control and monitoring of network traffic.

By default, the Cortex XDR agent will receive the default profile that contains a predefined configuration for each malware protection capability supported by the platform.

Configure a malware prevention profile

Configure a malware prevention profile on the Cortex XDR or XSIAM tenant.

  1. Add a new profile and define basic settings.

    1. Select EndpointsPolicy ManagementPreventionProfiles. Click +Add Profile, and select whether to create a new profile, or to import a profile from a file.

      Note

      New profiles based on imported profiles are added, and do not replace existing ones.

    2. Select the iOS platform, and Malware as the profile type.

    3. Click Next.

    4. For Profile Name, enter a unique name for the profile. The name can contain only letters, numbers, or spaces, and must be no more than 30 characters. The name will be visible from the list of profiles when you configure a policy rule.

    5. For Description, to provide additional context for the purpose or business reason for creating the profile, enter a profile description. For example, you might include an incident identification number or a link to a help desk ticket.

  2. Configure URL filtering to analyze and block or report malicious URLs, and to block or allow custom URLs.

    Note

    Blocking functionality is different for each security module. For SMS/MMS, Cortex XDR agent will move detected messages containing such URLs from unknown senders to the Junk folder.

    Item

    Options

    More details

    Action Mode

    • Block

    • Report

    • Disabled

    When the Cortex XDR agent detects malicious URLs, the Cortex XDR agent performs the configured action.

    To add numbers to the Block List, click +Add and enter the URL. Press Enter to add more URLs.

    To add URLs to the Allow List, define a list on the Legacy Agent Exceptions page.

  3. Configure Spam Reports to report calls and messages as spam.

    Item

    Options

    More details

    Spam Report

    • Enabled

    • Disabled

    Configure reporting of spam calls and messages to Cortex analysts.

  4. Configure Call and Messages Blocking for incoming calls and messages from known spam numbers.

    Item

    Options

    More details

    Action Mode

    • Block

    • Report

    • Disabled

    When the Cortex XDR agent detects incoming calls or messages from known spam numbers, the Cortex XDR agent performs the configured action.

    • To add numbers to the Block List, click +Add and enter the phone number. Press Enter to add more numbers.

    • To add numbers to the Allow List, define a list on the Legacy Agent Exceptions page.

    Note

    Ensure that the same numbers are not added multiple times with different leading zeros.

  5. Configure Safari Browser Security Module. This security module can provide proactive gating of suspicious sites accessed using Safari, and provides informative site analysis to the device user. This option is recommended for iOS devices that do not belong to your organization and do not use the Network Shield feature.

    Note

    To fully enable the Safari browser security module on the device side, each iOS device user must enable the Safari Safeguard module on the device, and grant it permission to work on all websites. If the iOS device user does not do this, the endpoint's operation status is reported as Partially Protected.

    The Safari browser security module will only function when the URL filtering module (see earlier in this procedure) is set to Block.

    Item

    Options

    More details

    Enforce use of Safari Security Module

    • Enabled

    • Disabled

    When set to Enabled, the Safari Safeguard security module displays "Required" on the Modules screen of the app. Full protection for Safari will only be active after the iOS device user has also activated it on the device. When this module is also activated on the device, alerts are forwarded to the tenant.

    When set to Disabled, and users decide to enable the module on their devices, alerts are visible locally on the iOS device only, and are not forwarded to the tenant.

    Safari malicious JS blocking

    • Enabled

    • Disabled

    When set to Enabled, the Cortex XDR agent blocks the entire page in Safari where malicious JS files are detected.

  6. Configure Network and EDR Security Module. This module lets you configure granular control and monitoring of network traffic on iOS-based supervised devices. The devices' profiles must be also configured for this on the MDM side as explained in the Cortex XDR Agent iOS Guide.

    Note

    Cortex XDR agent version 8.4 or higher are required for this feature.

    Item

    Options

    More details

    Auto detected malicious URL filtering

    • Enabled

    • Disabled

    When set to Enabled, the Cortex XDR agent automatically filters known malicious URLs.

    URL filtering

    • Enabled

    • Disabled

    When set to Enabled, the Cortex XDR agent filters URLs according to the lists of allowed and blocked URLs configured in the URL Filtering section above.

    Predefined Blocked Apps

    List of apps

    A list of commonly known apps that your organization may be interested in blocking on supervised devices is provided here. The Cortex XDR agent will block use of the selected apps. You can select one or more apps.

    Blocked Bundle IDs

    A Bundle ID is an app's unique identifier, in string format, that is used to identify the app in an app store. Communication will be blocked for any process with exactly the Bundle ID defined here, or for a Bundle ID that has the defined string as a suffix.

    For example, the Calculator app's Bundle ID is: com.apple.calculator. When you add com.apple.calculator to the list, the Cortex XDR agent app will block all of these Bundle IDs:

    • com.apple.calculator

    • H3DT34.com.apple.calculator

    • widget.com.apple.calculator

    To block apps according to Bundle ID, enter a Bundle ID and press Enter. To add another Bundle ID to the list, click +Add and repeat this process.

    Block List of Remote IPV4/IPV6 IP Address

    The Cortex XDR agent will block the IP addresses that you add to this field. Both IPV4 and IPv6 addresses are supported.

    To block apps according to IP address, enter an IP address with a subnet mask, a range, or an individual IP address, and press Enter. To add another IP address to the list, click +Add and repeat this process.

    Digest alerts

    • Enabled

    • Disabled

    Digest alerts are alerts that contain a summary of blocked network activity over a prolonged time period.

    When set to Enabled, the Cortex XDR agent sends digest alerts to the tenant.

    Digest alerts max frequency

    1 to 7 days

    When Digest alerts is enabled, you can limit the digest alert to no more than one per <selected number of days>.

    Max alerts per app

    • Hours

    • Minutes

    Limit alert notifications by the Cortex XDR agent app to one alert for each app per <selected period of time>.

    Max user notifications

    Hours

    Limit alert notifications by the Cortex XDR agent app to one user notification per <selected number of hours>.

  7. To save the profile, click Create.

Assign the profile to a prevention policy rule

  1. Select Endpoints → Policy Management → Prevention → Policy Rules.

  2. Do one of the following:

    • To create a new policy or import a policy, click +Add Policy and select whether to Create New or Import from File. Enter a meaningful Policy Name and Description.

    • Edit an existing policy rule.

    Note

    New imported policies are added, not replaced.

  3. For Platform, select iOS, and then for Malware, select the profile that you created.

  4. Click Next.

  5. Select the iOS devices to which you want to assign the policy.

  6. Click Done.

Last updated

Was this helpful?