Which of the following protection modules is checked first in the Cortex XDR Windows agent malware protection flow?
The first protection module that is checked in the Cortex XDR Windows agent malware protection flow is the Hash Verdict Determination. This module compares the hash of the executable file that is about to run on the endpoint with a list of known malicious hashes stored in the Cortex XDR cloud. If the hash matches a malicious hash, the agent blocks the execution and generates an alert.If the hash does not match a malicious hash, the agent proceeds to the next protection module, which is the Restriction Policy1.
The Hash Verdict Determination module is the first line of defense against malware, as it can quickly and efficiently prevent known threats from running on the endpoint. However, this module cannot protect against unknown or zero-day threats, which have no known hash signature.Therefore, the Cortex XDR agent relies on other protection modules, such as Behavioral Threat Protection, Child Process Protection, and Exploit Protection, to detect and block malicious behaviors and exploits that may occur during the execution of the file1.
Palo Alto Networks Cortex XDR Documentation, File Analysis and Protection Flow
Limited Time Offer
25%
Off
Cheryl
10 days agoIvan
11 days agoRichelle
24 days agoDorsey
5 days agoIsidra
28 days agoFrederick
10 days agoIra
17 days agoIra
18 days agoTrinidad
29 days agoAlva
1 months agoErinn
1 months agoKeshia
2 months agoMarla
2 months agoKeshia
2 months ago