<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Agent Tamper Protection Notification in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-tamper-protection-notification/m-p/460808#M1483</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191065"&gt;@RahulPrajapati&lt;/a&gt;&amp;nbsp;users cannot uninstall or disable any functionalities without the Agent password defined globally or in Agent settings profile applied to a host. If you have a PoC to demonstrate the bypass, we can definitely take a deep dive at it to fix the issue.&lt;/P&gt;&lt;P&gt;In short, you won't get a notification for such behavior at this point in time.&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jan 2022 06:16:29 GMT</pubDate>
    <dc:creator>bbarmanroy</dc:creator>
    <dc:date>2022-01-25T06:16:29Z</dc:date>
    <item>
      <title>Cortex XDR Agent Tamper Protection Notification</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-tamper-protection-notification/m-p/460796#M1481</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we get the notification on Cortex XDR Management console, if any user is trying to disable the XDR Agent protection and services ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 04:46:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-tamper-protection-notification/m-p/460796#M1481</guid>
      <dc:creator>RahulPrajapati</dc:creator>
      <dc:date>2022-01-25T04:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Agent Tamper Protection Notification</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-tamper-protection-notification/m-p/460808#M1483</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191065"&gt;@RahulPrajapati&lt;/a&gt;&amp;nbsp;users cannot uninstall or disable any functionalities without the Agent password defined globally or in Agent settings profile applied to a host. If you have a PoC to demonstrate the bypass, we can definitely take a deep dive at it to fix the issue.&lt;/P&gt;&lt;P&gt;In short, you won't get a notification for such behavior at this point in time.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 06:16:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-tamper-protection-notification/m-p/460808#M1483</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-01-25T06:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Agent Tamper Protection Notification</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-tamper-protection-notification/m-p/460850#M1489</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some local engineers had the uninstall password so we have changed it. I can see the Agent service stop logs from Agent Audit logs. But many of them can possibly means that system got shutdown and so Agent service got stop. But if any user tries to disable the agent service using cytool command. Can we know that information from the Agent audit logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 08:50:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-tamper-protection-notification/m-p/460850#M1489</guid>
      <dc:creator>RahulPrajapati</dc:creator>
      <dc:date>2022-01-25T08:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Agent Tamper Protection Notification</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-tamper-protection-notification/m-p/461055#M1491</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191065"&gt;@RahulPrajapati&lt;/a&gt;&amp;nbsp;you are correct - a shutdown will stop Agent services.&lt;/P&gt;&lt;P&gt;If a user is successfully able to stop one or more XDR agent services, that will be listed as an event in the Agent Audit logs. Unsuccessful attempts won't be listed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 01:40:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-tamper-protection-notification/m-p/461055#M1491</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-01-26T01:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Agent Tamper Protection Notification</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-tamper-protection-notification/m-p/509814#M2389</link>
      <description>&lt;P&gt;There must be a way :). Since the agent is watching every process, there must be a way to throw an alert, when something irregular happens to the Services??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 17:02:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-agent-tamper-protection-notification/m-p/509814#M2389</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-07-25T17:02:34Z</dc:date>
    </item>
  </channel>
</rss>

