Add a Malware Prevention Profile (Administrator Task)
From the Cortex XDR or XSIAM tenant, you can configure the action that Cortex XDR agents on iOS devices take for known malicious URLs and spam numbers. You can also configure granular control and moni
You can use Malware prevention profiles to configure the actions that Cortex XDR agents take when they detect known malicious URLs or spam numbers. You can also configure granular control and monitoring of network traffic.
By default, the Cortex XDR agent will receive the default profile that contains a predefined configuration for each malware protection capability supported by the platform.
Configure a malware prevention profile
Configure a malware prevention profile on the Cortex XDR or XSIAM tenant.
Add a new profile and define basic settings.
Select the iOS platform, and Malware as the profile type.
Click Next.
For Profile Name, enter a unique name for the profile. The name can contain only letters, numbers, or spaces, and must be no more than 30 characters. The name will be visible from the list of profiles when you configure a policy rule.
For Description, to provide additional context for the purpose or business reason for creating the profile, enter a profile description. For example, you might include an incident identification number or a link to a help desk ticket.
Configure URL filtering to analyze and block or report malicious URLs, and to block or allow custom URLs.
Note
Blocking functionality is different for each security module. For SMS/MMS, Cortex XDR agent will move detected messages containing such URLs from unknown senders to the Junk folder.
Item
Options
More details
Action Mode
Block
Report
Disabled
When the Cortex XDR agent detects malicious URLs, the Cortex XDR agent performs the configured action.
To add numbers to the Block List, click +Add and enter the URL. Press Enter to add more URLs.
To add URLs to the Allow List, define a list on the Legacy Agent Exceptions page.
Configure Spam Reports to report calls and messages as spam.
Item
Options
More details
Spam Report
Enabled
Disabled
Configure reporting of spam calls and messages to Cortex analysts.
Configure Call and Messages Blocking for incoming calls and messages from known spam numbers.
Item
Options
More details
Action Mode
Block
Report
Disabled
When the Cortex XDR agent detects incoming calls or messages from known spam numbers, the Cortex XDR agent performs the configured action.
To add numbers to the Block List, click +Add and enter the phone number. Press Enter to add more numbers.
To add numbers to the Allow List, define a list on the Legacy Agent Exceptions page.
Configure Safari Browser Security Module. This security module can provide proactive gating of suspicious sites accessed using Safari, and provides informative site analysis to the device user. This option is recommended for iOS devices that do not belong to your organization and do not use the Network Shield feature.
Note
To fully enable the Safari browser security module on the device side, each iOS device user must enable the Safari Safeguard module on the device, and grant it permission to work on all websites. If the iOS device user does not do this, the endpoint's operation status is reported as Partially Protected.
The Safari browser security module will only function when the URL filtering module (see earlier in this procedure) is set to Block.
Item
Options
More details
Enforce use of Safari Security Module
Enabled
Disabled
When set to Enabled, the Safari Safeguard security module displays "Required" on the Modules screen of the app. Full protection for Safari will only be active after the iOS device user has also activated it on the device. When this module is also activated on the device, alerts are forwarded to the tenant.
When set to Disabled, and users decide to enable the module on their devices, alerts are visible locally on the iOS device only, and are not forwarded to the tenant.
Safari malicious JS blocking
Enabled
Disabled
When set to Enabled, the Cortex XDR agent blocks the entire page in Safari where malicious JS files are detected.
Configure Network and EDR Security Module. This module lets you configure granular control and monitoring of network traffic on iOS-based supervised devices. The devices' profiles must be also configured for this on the MDM side as explained in the Cortex XDR Agent iOS Guide.
Item
Options
More details
Auto detected malicious URL filtering
Enabled
Disabled
When set to Enabled, the Cortex XDR agent automatically filters known malicious URLs.
URL filtering
Enabled
Disabled
When set to Enabled, the Cortex XDR agent filters URLs according to the lists of allowed and blocked URLs configured in the URL Filtering section above.
Predefined Blocked Apps
List of apps
A list of commonly known apps that your organization may be interested in blocking on supervised devices is provided here. The Cortex XDR agent will block use of the selected apps. You can select one or more apps.
Blocked Bundle IDs
A Bundle ID is an app's unique identifier, in string format, that is used to identify the app in an app store. Communication will be blocked for any process with exactly the Bundle ID defined here, or for a Bundle ID that has the defined string as a suffix.
For example, the Calculator app's Bundle ID is: com.apple.calculator. When you add com.apple.calculator to the list, the Cortex XDR agent app will block all of these Bundle IDs:
com.apple.calculator
H3DT34.com.apple.calculator
widget.com.apple.calculator
To block apps according to Bundle ID, enter a Bundle ID and press Enter. To add another Bundle ID to the list, click +Add and repeat this process.
Block List of Remote IPV4/IPV6 IP Address
The Cortex XDR agent will block the IP addresses that you add to this field. Both IPV4 and IPv6 addresses are supported.
To block apps according to IP address, enter an IP address with a subnet mask, a range, or an individual IP address, and press Enter. To add another IP address to the list, click +Add and repeat this process.
Digest alerts
Enabled
Disabled
Digest alerts are alerts that contain a summary of blocked network activity over a prolonged time period.
When set to Enabled, the Cortex XDR agent sends digest alerts to the tenant.
Digest alerts max frequency
1 to 7 days
When Digest alerts is enabled, you can limit the digest alert to no more than one per <selected number of days>.
Max alerts per app
Hours
Minutes
Limit alert notifications by the Cortex XDR agent app to one alert for each app per <selected period of time>.
Max user notifications
Hours
Limit alert notifications by the Cortex XDR agent app to one user notification per <selected number of hours>.
To save the profile, click Create.
Assign the profile to a prevention policy rule
Select Endpoints → Policy Management → Prevention → Policy Rules.
For Platform, select iOS, and then for Malware, select the profile that you created.
Click Next.
Select the iOS devices to which you want to assign the policy.
Click Done.
Last updated
Was this helpful?
