Cortex XDR_Behavioral threat detected (rule: excel_virus)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Cortex XDR_Behavioral threat detected (rule: excel_virus)

L1 Bithead

Hello All,

 

Greetings for the day!

 

We are getting multiple high severity alerts/incidents related with excel files because of Behavioral threat detected (rule: excel_virus).

 

Within the time span of 4 hours we have received 28 high severity alerts in 12 different hostnames. Also, the high severity alert is getting generated for the newly created excel file in the system without any macro or function being used.

 

Please help to answer the below queries-

  1. On what basis these alerts are getting generated on legitimate files?
  2. What need to be done to prevent these alerts from getting generated without any risk involved?
  3. How these incidents can be thoroughly analyzed as for each & every file we can not ask the user about the source or legitimacy of the file?

 

Regards,

Sakshi Seth

2 REPLIES 2

L4 Transporter

Hello @Seth_Sakshi ,

 

Thanks for reaching out on LiveCommunity!

 

To answer your question, Cortex XDR uses WF verdict and local analysis to provide the verdict of file.

 

You can go through below training to learn how to do IR and fine tune the alerts:

https://live.paloaltonetworks.com/t5/customer-journey-prevent/scale-amp-optimize-xdr-prevent/ta-p/39...

 

If you want to confirm the reputation, you can involve SE or submit the file to TAC to confirm the reputation.

 

Regards.

Ashutosh Patil

L4 Transporter

Hello @Seth_Sakshi 

 

Thanks for reaching out on LiveCommunity!

This scenario require analysis of alert data to determine the root cause for alert. Hence please open a support case.

 

  • 447 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!