Manage endpoint prevention profiles

You can manage the endpoint prevention profiles of your Cortex XDR agent endpoints in various ways, including editing, duplicating, and populating endpoint prevention policy rules.

After you create and customize your endpoint prevention profiles, you can manage them from the Prevention Profiles page as needed.

View the prevention policy rules that use a specific prevention profile

Before you modify or delete a profile, you can check which policy rules, if any, use the profile.

  • From Inventory → Endpoints → Policy Management → Prevention → Profiles, right-click the profile and select View policy Rules.

Cortex XSIAM opens the Prevention Policy Rules page on a new tab. This page is filtered, and only displays the rules that use the profile that you selected.

Edit, export, duplicate, or delete an endpoint prevention profile

Edit a profile:

From Inventory → Endpoints → Policy Management → Prevention → Profiles, right-click the profile and select Edit.

Make your changes, and then click Save.

Export a profile:

From Inventory → Endpoints → Policy Management → Prevention → Profiles, right-click the profile and select Export Profile.

Click Export. The profile is downloaded to your computer.

Duplicate a profile:

From Inventory → Endpoints → Policy Management → Prevention → Profiles, right-click the prevention profile and select Save as New. A new profile is displayed, containing the values from the profile that you selected.

Edit the profile name and description, edit any values that you want to change, and then click Create.

Populate a new prevention policy rule with your new profile.

Delete a profile:

If necessary, delete or detach any policy rules that use the profile before attempting to delete it.

From Inventory → Endpoints → Policy Management → Prevention → Profiles, locate the profile that you want to remove. The profile's Usage Count cell must have a 0 (zero) value.

Right-click the prevention profile and select Delete.

To confirm the deletion, click Yes.

Populate a new prevention policy rule with a prevention profile

From Inventory → Endpoints → Policy Management → Prevention → Profiles, right-click the profile and select Create a new policy rule using this profile.

Cortex XSIAM automatically populates the Platform selection based on your profile configuration, and assigns the profile based on the profile type.

For Policy Name, enter a meaningful name, and optionally, add a description for the policy rule.

Assign any additional profiles that you want to apply to your policy rule, and click Next. A list of endpoints is displayed.

Select the target endpoints for the policy rule, or use the filters to define criteria for the policy rule to apply, and then click Next.

Review the policy rule summary, and then click Done.