<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Researcher for evading Cortex XDR  &amp;amp; my PoC XP in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/researcher-for-evading-cortex-xdr-amp-my-poc-xp/m-p/458898#M1448</link>
    <description>&lt;P&gt;Dear Community,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here I have found a researcher which evaded Cortex XDR protection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;A href="https://0xsp.com/security%20research%20&amp;amp;%20development%20(SRD)/defeat-the-castle-bypass-av-advanced-xdr-solutions" target="_blank"&gt;https://0xsp.com/security%20research%20&amp;amp;%20development%20(SRD)/defeat-the-castle-bypass-av-advanced-xdr-solutions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Are there any connections to researcher like the one in the link above to penetrate cortex xdr?&amp;nbsp;&lt;/P&gt;&lt;P&gt;What can you say to the evasion technic frohe the researcher above? Will or is this allready fixed?&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From my PoC expirience we had 2 issues:&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Incident triggered for some files on the disk, which still existed on the disk. I deleted them manualy. After this I tried to quarantaine or delete them through Cortex APP leaded into a BSOD on Win10.&lt;/P&gt;&lt;P&gt;2. We had installed the Agent on a terminal Server. Used an Java based program for several users which was missconfigured without any RAM restriction on the jvm (now on 512m). So the system went sometimes in struggle of free virtual RAM. In this Situation the agent was disabled by missing Ressourcen.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We struggled about 3 days, because Real RAM was enough, but jvm used the virtual RAM setting and this wasnt adjusted for non restricted jvm RAM setting.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 15 Jan 2022 13:01:18 GMT</pubDate>
    <dc:creator>Cyber1985</dc:creator>
    <dc:date>2022-01-15T13:01:18Z</dc:date>
    <item>
      <title>Researcher for evading Cortex XDR  &amp; my PoC XP</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/researcher-for-evading-cortex-xdr-amp-my-poc-xp/m-p/458898#M1448</link>
      <description>&lt;P&gt;Dear Community,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here I have found a researcher which evaded Cortex XDR protection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;A href="https://0xsp.com/security%20research%20&amp;amp;%20development%20(SRD)/defeat-the-castle-bypass-av-advanced-xdr-solutions" target="_blank"&gt;https://0xsp.com/security%20research%20&amp;amp;%20development%20(SRD)/defeat-the-castle-bypass-av-advanced-xdr-solutions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Are there any connections to researcher like the one in the link above to penetrate cortex xdr?&amp;nbsp;&lt;/P&gt;&lt;P&gt;What can you say to the evasion technic frohe the researcher above? Will or is this allready fixed?&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From my PoC expirience we had 2 issues:&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Incident triggered for some files on the disk, which still existed on the disk. I deleted them manualy. After this I tried to quarantaine or delete them through Cortex APP leaded into a BSOD on Win10.&lt;/P&gt;&lt;P&gt;2. We had installed the Agent on a terminal Server. Used an Java based program for several users which was missconfigured without any RAM restriction on the jvm (now on 512m). So the system went sometimes in struggle of free virtual RAM. In this Situation the agent was disabled by missing Ressourcen.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We struggled about 3 days, because Real RAM was enough, but jvm used the virtual RAM setting and this wasnt adjusted for non restricted jvm RAM setting.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jan 2022 13:01:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/researcher-for-evading-cortex-xdr-amp-my-poc-xp/m-p/458898#M1448</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-01-15T13:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: Researcher for evading Cortex XDR  &amp; my PoC XP</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/researcher-for-evading-cortex-xdr-amp-my-poc-xp/m-p/458997#M1453</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206384"&gt;@Cyber1985&lt;/a&gt;&amp;nbsp;From the article, it appears that the bypass attempts were blocked, or am I reading it incorrectly?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For your endpoint issues,&lt;BR /&gt;for #1, are you able to reproduce the issue or is it a one-time incident? Does the BSOD happen every time you try to quarantine or delete a file?&lt;BR /&gt;for #2, it is not clear from your explanation if the issue is related to Cortex XDR agent or the Java-based application. It might be an issue with the JVM's on the hosts and not Cortex XDR. If your issue persists, please create a support ticket at support.paloaltonetworls.com with agent logs for the corresponding teams to analyse the issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 04:41:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/researcher-for-evading-cortex-xdr-amp-my-poc-xp/m-p/458997#M1453</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-01-17T04:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: Researcher for evading Cortex XDR  &amp; my PoC XP</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/researcher-for-evading-cortex-xdr-amp-my-poc-xp/m-p/459006#M1455</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the fast reply!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I understood the final showdown can bee seen in the last Video and the Text above.&amp;nbsp;&lt;/P&gt;&lt;P&gt;#1 could be reproduced, but our PoC is over and there wasnt enough time to submit a Ticket.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#2 You are right, the issue came from jvm. I Dont except a solution, i wanted to share my XP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 06:25:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/researcher-for-evading-cortex-xdr-amp-my-poc-xp/m-p/459006#M1455</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-01-17T06:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: Researcher for evading Cortex XDR  &amp; my PoC XP</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/researcher-for-evading-cortex-xdr-amp-my-poc-xp/m-p/459019#M1456</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206384"&gt;@Cyber1985&lt;/a&gt;&amp;nbsp;What I see in the last gif is the Cobalt Strike beacon being detected and a Cortex XDR agent popup that says "Cortex XDR agent has blocked a malicious activity!", which contradicts the text. It's a bit unclear here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cortex XDR engineering teams continuously looks for evasion techniques and bakes appropriate detection and/or prevention techniques to mitigate such actions. My recommendation is to try to recreate the POC and if successful, reach out to your account teams who will guide you through the next steps.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 05:59:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/researcher-for-evading-cortex-xdr-amp-my-poc-xp/m-p/459019#M1456</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-01-18T05:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: Researcher for evading Cortex XDR  &amp; my PoC XP</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/researcher-for-evading-cortex-xdr-amp-my-poc-xp/m-p/461304#M1494</link>
      <description>&lt;P&gt;hello!&amp;nbsp;&lt;/P&gt;&lt;P&gt;The correction of the above mentioned evation technique was allredy fixed I was told by the researcher himself.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For issue#1: yes, everytime I tried to delete or quarantined a not existing file I got an BSOD.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Issue#2: yes indeed, the root of the problem was caused by not well configured JVMs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 06:36:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/researcher-for-evading-cortex-xdr-amp-my-poc-xp/m-p/461304#M1494</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-01-27T06:36:33Z</dc:date>
    </item>
    <item>
      <title>Re: Researcher for evading Cortex XDR  &amp; my PoC XP</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/researcher-for-evading-cortex-xdr-amp-my-poc-xp/m-p/461383#M1500</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206384"&gt;@Cyber1985&lt;/a&gt;&amp;nbsp;Thank you for reaching out and confirming the point on XDR capabilities.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For your case where the endpoint is experiencing a BSOD for triggering a File Search and Destroy for files that are deleted or quarantined, I recommend you to open a support ticket and upload the support file for the affected endpoint. Please ensure your endpoint is running a supported version of Cortex XDR and has not reached &lt;A href="https://www.paloaltonetworks.com/services/support/end-of-life-announcements/end-of-life-summary" target="_self"&gt;End-of-life&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 13:06:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/researcher-for-evading-cortex-xdr-amp-my-poc-xp/m-p/461383#M1500</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-01-27T13:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: Researcher for evading Cortex XDR  &amp; my PoC XP</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/researcher-for-evading-cortex-xdr-amp-my-poc-xp/m-p/461393#M1501</link>
      <description>&lt;P&gt;what agent version and what content version was this performed with?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 13:29:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/researcher-for-evading-cortex-xdr-amp-my-poc-xp/m-p/461393#M1501</guid>
      <dc:creator>P.Jacob</dc:creator>
      <dc:date>2022-01-27T13:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: Researcher for evading Cortex XDR  &amp; my PoC XP</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/researcher-for-evading-cortex-xdr-amp-my-poc-xp/m-p/461723#M1508</link>
      <description>&lt;P&gt;It was around Version&amp;nbsp;7.4.2.3569.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are out of PoC. So we cannot open any support case.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 07:19:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/researcher-for-evading-cortex-xdr-amp-my-poc-xp/m-p/461723#M1508</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-01-28T07:19:30Z</dc:date>
    </item>
  </channel>
</rss>

