> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/administrator-tasks/prepare-for-installation-administrator-task/add-a-malware-prevention-profile-administrator-task.md).

# Add a Malware Prevention Profile (Administrator Task)

You can use Malware prevention profiles to configure the actions that Cortex XDR agents take when they detect known malicious URLs or spam numbers. You can also configure granular control and monitoring of network traffic.

By default, the Cortex XDR agent will receive the default profile that contains a predefined configuration for each malware protection capability supported by the platform.

**Configure a malware prevention profile**

Configure a malware prevention profile on the Cortex XDR or XSIAM tenant.

1. Add a new profile and define basic settings.
   1. Select **Endpoints** → **Policy Management** → **Prevention** → **Profiles**. Click **+Add Profile**, and select whether to create a new profile, or to import a profile from a file.

      <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>New profiles based on imported profiles are added, and do not replace existing ones.</p></div>
   2. Select the **iOS** platform, and **Malware** as the profile type.
   3. Click **Next**.
   4. For **Profile Name**, enter a unique name for the profile. The name can contain only letters, numbers, or spaces, and must be no more than 30 characters. The name will be visible from the list of profiles when you configure a policy rule.
   5. For **Description**, to provide additional context for the purpose or business reason for creating the profile, enter a profile description. For example, you might include an incident identification number or a link to a help desk ticket.
2. Configure **URL filtering** to analyze and block or report malicious URLs, and to block or allow custom URLs.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Blocking functionality is different for each security module. For SMS/MMS, Cortex XDR agent will move detected messages containing such URLs from unknown senders to the <strong>Junk</strong> folder.</p></div>

   | Item        | Options                                                 | More details                                                                                                                                                                                                                                                                                                                                                                  |
   | ----------- | ------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Action Mode | <ul><li>Block</li><li>Report</li><li>Disabled</li></ul> | <p>When the Cortex XDR agent detects malicious URLs, the Cortex XDR agent performs the configured action.</p><p>To add numbers to the <strong>Block List</strong>, click <strong>+Add</strong> and enter the URL. Press Enter to add more URLs.</p><p>To add URLs to the <strong>Allow List</strong>, define a list on the <strong>Legacy Agent Exceptions</strong> page.</p> |
3. Configure **Spam Reports** to report calls and messages as spam.

   | Item        | Options                                    | More details                                                       |
   | ----------- | ------------------------------------------ | ------------------------------------------------------------------ |
   | Spam Report | <ul><li>Enabled</li><li>Disabled</li></ul> | Configure reporting of spam calls and messages to Cortex analysts. |
4. Configure **Call and Messages Blocking** for incoming calls and messages from known spam numbers.

   | Item        | Options                                                 | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
   | ----------- | ------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Action Mode | <ul><li>Block</li><li>Report</li><li>Disabled</li></ul> | <p>When the Cortex XDR agent detects incoming calls or messages from known spam numbers, the Cortex XDR agent performs the configured action.</p><ul><li>To add numbers to the <strong>Block List</strong>, click <strong>+Add</strong> and enter the phone number. Press Enter to add more numbers.</li><li>To add numbers to the <strong>Allow List</strong>, define a list on the <strong>Legacy Agent Exceptions</strong> page.</li></ul><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Ensure that the same numbers are not added multiple times with different leading zeros.</p></div> |
5. Configure **Safari Browser Security Module**. This security module can provide proactive gating of suspicious sites accessed using Safari, and provides informative site analysis to the device user. This option is recommended for iOS devices that do not belong to your organization and do not use the Network Shield feature.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>To fully enable the Safari browser security module on the device side, each iOS device user must enable the Safari Safeguard module on the device, and grant it permission to work on all websites. If the iOS device user does not do this, the endpoint's operation status is reported as <strong>Partially Protected</strong>.</p><p>The Safari browser security module will only function when the URL filtering module (see earlier in this procedure) is set to <strong>Block</strong>.</p></div>

   | Item                                  | Options                                    | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
   | ------------------------------------- | ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Enforce use of Safari Security Module | <ul><li>Enabled</li><li>Disabled</li></ul> | <p>When set to <strong>Enabled</strong>, the Safari Safeguard security module displays "Required" on the <strong>Modules</strong> screen of the app. Full protection for Safari will only be active after the iOS device user has also activated it on the device. When this module is also activated on the device, alerts are forwarded to the tenant.</p><p>When set to <strong>Disabled</strong>, and users decide to enable the module on their devices, alerts are visible locally on the iOS device only, and are not forwarded to the tenant.</p> |
   | Safari malicious JS blocking          | <ul><li>Enabled</li><li>Disabled</li></ul> | When set to **Enabled**, the Cortex XDR agent blocks the entire page in Safari where malicious JS files are detected.                                                                                                                                                                                                                                                                                                                                                                                                                                     |
6. Configure **Network and EDR Security Module**. This module lets you configure granular control and monitoring of network traffic on iOS-based supervised devices. The devices' profiles must be also configured for this on the MDM side as explained in the Cortex XDR Agent iOS Guide.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Cortex XDR agent version 8.4 or higher are required for this feature.</p></div>

   | Item                                      | Options                                    | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
   | ----------------------------------------- | ------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Auto detected malicious URL filtering     | <ul><li>Enabled</li><li>Disabled</li></ul> | When set to **Enabled**, the Cortex XDR agent automatically filters known malicious URLs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
   | URL filtering                             | <ul><li>Enabled</li><li>Disabled</li></ul> | When set to **Enabled**, the Cortex XDR agent filters URLs according to the lists of allowed and blocked URLs configured in the **URL Filtering** section above.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
   | Predefined Blocked Apps                   | List of apps                               | A list of commonly known apps that your organization may be interested in blocking on supervised devices is provided here. The Cortex XDR agent will block use of the selected apps. You can select one or more apps.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
   | Blocked Bundle IDs                        |                                            | <p>A Bundle ID is an app's unique identifier, in string format, that is used to identify the app in an app store. Communication will be blocked for any process with exactly the Bundle ID defined here, or for a Bundle ID that has the defined string as a suffix.</p><p>For example, the Calculator app's Bundle ID is: com.apple.calculator. When you add com.apple.calculator to the list, the Cortex XDR agent app will block all of these Bundle IDs:</p><ul><li>com.apple.calculator</li><li>H3DT34.com.apple.calculator</li><li>widget.com.apple.calculator</li></ul><p>To block apps according to Bundle ID, enter a Bundle ID and press Enter. To add another Bundle ID to the list, click <strong>+Add</strong> and repeat this process.</p> |
   | Block List of Remote IPV4/IPV6 IP Address |                                            | <p>The Cortex XDR agent will block the IP addresses that you add to this field. Both IPV4 and IPv6 addresses are supported.</p><p>To block apps according to IP address, enter an IP address with a subnet mask, a range, or an individual IP address, and press Enter. To add another IP address to the list, click <strong>+Add</strong> and repeat this process.</p>                                                                                                                                                                                                                                                                                                                                                                                  |
   | Digest alerts                             | <ul><li>Enabled</li><li>Disabled</li></ul> | <p>Digest alerts are alerts that contain a summary of blocked network activity over a prolonged time period.</p><p>When set to <strong>Enabled</strong>, the Cortex XDR agent sends digest alerts to the tenant.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
   | Digest alerts max frequency               | 1 to 7 days                                | When **Digest alerts** is enabled, you can limit the digest alert to no more than one per \<selected number of days>.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
   | Max alerts per app                        | <ul><li>Hours</li><li>Minutes</li></ul>    | Limit alert notifications by the Cortex XDR agent app to one alert for each app per \<selected period of time>.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
   | Max user notifications                    | Hours                                      | Limit alert notifications by the Cortex XDR agent app to one user notification per \<selected number of hours>.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
7. To save the profile, click **Create**.

**Assign the profile to a prevention policy rule**

1. Select Endpoints → Policy Management → Prevention → Policy Rules.
2. Do one of the following:

   * To create a new policy or import a policy, click **+Add Policy** and select whether to **Create New** or **Import from File**. Enter a meaningful **Policy Name** and **Description**.
   * Edit an existing policy rule.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>New imported policies are added, not replaced.</p></div>
3. For **Platform**, select **iOS**, and then for **Malware**, select the profile that you created.
4. Click **Next**.
5. Select the iOS devices to which you want to assign the policy.
6. Click **Done**.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.1/administrator-tasks/prepare-for-installation-administrator-task/add-a-malware-prevention-profile-administrator-task.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
