- Joined
- Jan 8, 2019
- Messages
- 56,623
- Solutions
- 2
- Reputation
- 32
- Reaction score
- 100,456
- Points
- 2,313
- Credits
- 32,750
6 Years of Service
76%

This tool is meant to be used during Red Team Assessments and to audit the XDR Settings.
With this tool its possible to parse the Database Lock Files of the Cortex XDR Agent by Palo Alto Networks and extract Agent Settings, the Hash and Salt of the Uninstall Password, as well as possible Exclusions.
Supported Extractions
Uninstall Password Hash & Salt
Excluded Signer Names
DLL Security Exclusions & Settings
PE Security Exclusions & Settings
Office Files Security Exclusions & Settings
Credential Gathering Module Exclusions
Webshell Protection Module Exclusions
Childprocess Executionchain Exclusions
Behavorial Threat Module Exclusions
Local Malware Scan Module Exclusions
Memory Protection Module Status
Global Hash Exclusions
Ransomware Protection Module Modus & Settings
To see this hidden content, you must like this content.