Add a global endpoint policy exception ↗
Learn how to define and manage global endpoint policy exceptions in Cortex XSIAM.
As an alternative to endpoint-specific policy exceptions, define global exceptions for all endpoints. On the Global Exceptions page, manage organization-wide exceptions for every platform. Profiles assigned to targets outside your user scope are locked.
Important
- Starting with version 1.3, manage Global Endpoint Policy exceptions centrally in Legacy Agent Exceptions management.
- Before managing prevention profile exceptions from Exception Configuration, migrate existing global exceptions.
- Migrated rules appear in Settings → Exception Configurations → Legacy Agent Exceptions. See Exception configuration.
- To create new global endpoint policy exceptions from Legacy Agent Exceptions, see Add a legacy exception rule for endpoints.
- If you do not migrate legacy exceptions, continue adding exceptions as described here.
Add a global process exception
Configure centralized exception rules for Cortex XSIAM protection and prevention actions.
- Go to Inventory → Endpoints → Policy Management → Policy Exceptions.
- Select Process exceptions.
- Select the operating system.
- Enter the process name.
- Select the endpoint protection modules that allow the process to run. The list contains modules relevant to the selected operating system.
- Select All to apply the exception to all security modules.
- Select Disable Injection to apply the exception to all exploit security modules.
- Click the adjacent arrow to add the exception.
- After adding all exceptions, select Save.
The new exception applies across all rules and policies. To edit or delete it, select the exception and click the relevant icon.
Add a global support exception
Configure centralized support exception rules for Cortex XSIAM protection and prevention actions.
- Go to Inventory → Endpoints → Prevention → Global Exceptions.
- Select Support Exceptions. Import the JSON file from Palo Alto Networks Support. Browse for the file or drag and drop it onto the page.
- Click Save.
The new support exception applies across all rules and policies.
Add a behavioral threat protection rule exception
Create a global exception for a Behavioral Threat rule you want to allow.
- Right-click the BTP issue and select Create issue exception.
- Review the platform and rule name. Choose the required exception criteria.
- From Scope, select Global or select a profile.
- Click Create.
The exception applies across all rules and policies. Click Generating Issue ID to return to the source issue. To delete an exception, select it and click X.
You cannot edit global exceptions generated from BTP security events.
Use recommended exception criteria
Use Cortex XSIAM recommended fields to define precise exception criteria.
-
Select the criterion that triggered the alert.
Select only one criterion per alert. Create a separate exception for each additional criterion.
- Select one or more displayed parameters relevant to the exception.
-
Edit an editable parameter if needed.
Select at least one parameter. Cortex XSIAM validates entered values. Wildcards are supported, but use specific values. Some parameters are not editable.
Use CGO information
Select CGO attributes to define general exception criteria:
- CGO hash: Causality Group Owner (CGO) hash value.
- CGO signer: CGO signer entity. Available for Windows and Mac only.
- CGO process path: Directory path of the CGO process.
- CGO command arguments: Available only with CGO process path and Cortex XDR Agent 7.5 or later. Check each relevant command argument's full path in quotation marks. Edit displayed paths if needed.
Add a global credential gathering protection exception
- Right-click the Credential Gathering Protection issue and select Create issue exception.
- Review the platform and module name. Select the required options:
- CGO hash: Causality Group Owner hash value.
- CGO signer: CGO signer entity. Available for Windows and Mac only.
- CGO process path: Directory path of the CGO process.
- CGO command arguments: Available only with CGO process path. Check each relevant command argument's full path in quotation marks. Edit displayed paths if needed.
- From Exception Scope, select Global.
- Click Create.
The exception applies across all rules and policies. Click Generating Issue ID to return to the source issue. To delete it, select it and click X.
You cannot edit global exceptions generated from Credential Gathering Protection security events.
Add a global anti webshell protection exception
- Right-click the Anti Webshell Protection issue and select Create issue exception.
- Review the platform and module name. Select CGO hash, CGO signer, CGO process path, or CGO command arguments as needed. Command arguments require CGO process path and Cortex XDR Agent 7.5 or later. From Exception Scope, select Global.
- Click Create.
The exception applies across all rules and policies. Click Generating Issue ID to return to the source issue. To delete it, select it and click X.
You cannot edit global exceptions generated from Anti Webshell Protection security events.
Add a global local analysis rules exception
- Right-click the Local Analysis issue and select Create issue exception.
- Review the platform and rule name, then set Exception Scope to Global.
- Click Add.
The exception applies across all rules and policies. It allows every rule that triggered the issue. You cannot allow only selected rules. Click Generating Issue ID to return to the source issue. To delete the exception, select it and click X. You cannot edit exceptions generated from local analysis security events.
Review advanced analysis exceptions
Advanced Analysis provides secondary validation for exploit protection issues. Cortex XSIAM analyzes issue data sent by the Cortex XDR agent. When an issue is benign, Cortex XSIAM can automatically create exceptions and distribute updated policy to endpoints.
Enable automatic Advanced Analysis exceptions in Settings → Configurations → General → Agent Configurations.
Each exception displays the platform, exception name, and relevant issue ID. Click Generating Issue ID to view issue details.
Add a global digital signer exception
- Right-click a trusted Digital Signer Restriction issue and select Create issue exception.
- Review the platform, signer, and issue ID. Set Exception Scope to Global.
- Click Add.
The exception applies across all rules and policies. Click Generating Issue ID to return to the source issue. To delete it, select it and click X. You cannot edit exceptions generated from Digital Signer Restriction security events.
Add a global Java deserialization exception
- Right-click a Suspicious Input Desensitization issue and select Create issue exception.
- Review the platform, process, Java executable, and issue ID. Set Exception Scope to Global.
- Click Add.
The exception applies across all rules and policies. Click Generating Issue ID to return to the source issue. To delete it, select it and click X. You cannot edit exceptions generated from Java deserialization security events.
Add a global local file threat examination exception
- Right-click a Local Threat Detected issue for a PHP file and select Create issue exception.
- Review the process, path, and hash. Set Exception Scope to Global.
- Click Add.
The PHP file exception applies across all rules and policies. Click Generating Issue ID to return to the source issue. To delete it, select it and click X. You cannot edit exceptions generated from local file threat examination security events.
Add a global Gatekeeper Enhancement exception
Create an exception for a specific bundle or source-child combination. Gatekeeper Enhancement remains active for other child processes.
- Right-click the Gatekeeper Enhancement issue and select Create issue exception.
- Review the platform, source process, target process, and issue ID. Set Exception Scope to Global.
- Click Add.
The source and target process exception applies across all rules and policies. Click Generating Issue ID to return to the source issue. To delete it, select it and click X. You cannot edit exceptions generated from Gatekeeper Enhancement security events.
Import and export exceptions
Select + Import/Export to export the exceptions list or import exceptions from a file.
Exported files use Base64 encoding and cannot be edited.