<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex xdr did not detect malware, what good is it? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/474401#M1720</link>
    <description>&lt;P&gt;Thanks for quick reply , I will refer this surely .&lt;/P&gt;</description>
    <pubDate>Fri, 18 Mar 2022 17:49:59 GMT</pubDate>
    <dc:creator>Balaraju</dc:creator>
    <dc:date>2022-03-18T17:49:59Z</dc:date>
    <item>
      <title>Cortex xdr did not detect malware, what good is it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/339318#M207</link>
      <description>&lt;P&gt;Cortex XDR did not detect malware, what good is it?&lt;/P&gt;&lt;P&gt;I got this scan with&amp;nbsp;mal warebytes.&amp;nbsp; 41 detected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SimonTan_0-1595020002980.jpeg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26895iEB607E950FD1B72C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SimonTan_0-1595020002980.jpeg" alt="SimonTan_0-1595020002980.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 21:41:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/339318#M207</guid>
      <dc:creator>SimonTan</dc:creator>
      <dc:date>2020-07-17T21:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex xdr did not detect malware, what good is it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/339329#M208</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/137998"&gt;@SimonTan&lt;/a&gt;-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just curious, did you try to run these binaries or leverage a scan.&amp;nbsp; What enforcement did you specify in your profiles / policy rules?&amp;nbsp; On the malware side there are several checks:&lt;/P&gt;&lt;P&gt;WildFire&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;WF Static Analysis&lt;/LI&gt;&lt;LI&gt;Machine Learning&lt;/LI&gt;&lt;LI&gt;Dynamic Analysis&lt;/LI&gt;&lt;LI&gt;Bare Metal&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;for unknown, the local analysis should do the examination at the point of execution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition to the malware prevention, Cortex XDR includes behavior threat protection, anti-ransomware, password theft protection, child process protection, and approximately 30 ways to exploitation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are using a scan for dormant malware, it is not the same as having all of the different protection levels that are leveraged during point of execution.&amp;nbsp; Are you able to share any hash / artifact info for verification?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 22:13:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/339329#M208</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-07-17T22:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex xdr did not detect malware, what good is it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/339852#M210</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/137998"&gt;@SimonTan&lt;/a&gt;-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would actually be happy to set up a Zoom with you to look over your configuration.&amp;nbsp; Based on your screenshot from MB, I believe that you may not have Cortex XDR configured to your needs.&amp;nbsp; For instance, in your screenshot, I see a large number of Potentially Unwanted Applications.&amp;nbsp; These are not malware.&amp;nbsp; Cortex XDR can be configured to treat these the same as malware.&amp;nbsp; On the malware side, I'd be very interested in checking into these as well.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if you would like to set up a session.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2020 15:50:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/339852#M210</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-07-21T15:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex xdr did not detect malware, what good is it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/339862#M211</link>
      <description>&lt;P&gt;how to retrieve a support file&amp;nbsp; and malware scan log?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SimonTan_0-1595351803583.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26954iA79D10D21E7AD2A3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SimonTan_0-1595351803583.png" alt="SimonTan_0-1595351803583.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2020 17:17:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/339862#M211</guid>
      <dc:creator>SimonTan</dc:creator>
      <dc:date>2020-07-21T17:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex xdr did not detect malware, what good is it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/339926#M212</link>
      <description>&lt;P&gt;Right click on that entry and select Additional Data.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dfalcon_0-1595359444215.png" style="width: 548px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26956i6CC493E027F19400/image-dimensions/548x100/is-moderation-mode/true?v=v2" width="548" height="100" role="button" title="dfalcon_0-1595359444215.png" alt="dfalcon_0-1595359444215.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Once in the details screen, right click on the entry in the list to download the TSF.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dfalcon_1-1595359535378.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26957iD0F3582E22BE437A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="dfalcon_1-1595359535378.png" alt="dfalcon_1-1595359535378.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2020 19:26:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/339926#M212</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-07-21T19:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex xdr did not detect malware, what good is it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/339930#M213</link>
      <description>&lt;P&gt;On the malware scan log.&amp;nbsp; Same thing.&amp;nbsp; Right click on the entry within the All Actions interface and select additional data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From there, locate the entry, right-click and select View Related Alerts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dfalcon_0-1595359693953.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26958i7CB8707F4B232FE5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="dfalcon_0-1595359693953.png" alt="dfalcon_0-1595359693953.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2020 19:28:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/339930#M213</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-07-21T19:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex xdr did not detect malware, what good is it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/339933#M214</link>
      <description>&lt;P&gt;got it, send file to the tech and see what they say.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2020 19:48:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/339933#M214</guid>
      <dc:creator>SimonTan</dc:creator>
      <dc:date>2020-07-21T19:48:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex xdr did not detect malware, what good is it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/474394#M1718</link>
      <description>&lt;P&gt;Hello , Is there any document or link which can summarise all the protection capabilities of Cortex XDR ? There seem to be many modules/techniques&amp;nbsp; but what is lacking is not all are listed at one place and its difficult to understand how it all works in real world and deliver protection , so list all protection capabilities/modules and give a brief of what each of them achieve .&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2022 17:16:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/474394#M1718</guid>
      <dc:creator>Balaraju</dc:creator>
      <dc:date>2022-03-18T17:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex xdr did not detect malware, what good is it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/474400#M1719</link>
      <description>&lt;P&gt;Please take a look at:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-concepts/endpoint-protection-modules.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-concepts/endpoint-protection-modules.html&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-concepts/analysis-and-protection-flow.html#idc8514e04-490b-498a-b9ca-b68dfc5be3d4" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-concepts/analysis-and-protection-flow.html#idc8514e04-490b-498a-b9ca-b68dfc5be3d4&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Let me know if this helps.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2022 17:38:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/474400#M1719</guid>
      <dc:creator>kcross</dc:creator>
      <dc:date>2022-03-18T17:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex xdr did not detect malware, what good is it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/474401#M1720</link>
      <description>&lt;P&gt;Thanks for quick reply , I will refer this surely .&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2022 17:49:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/474401#M1720</guid>
      <dc:creator>Balaraju</dc:creator>
      <dc:date>2022-03-18T17:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex xdr did not detect malware, what good is it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/474439#M1721</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/137998"&gt;@SimonTan&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;do not think of CXDR as a regular AV non stop scanning everything, we are not doing that. Even though you can schedule periodic scans we do not recommend to do then daily or frequently. This consumes a huge amount of resources to discover the known malicious files which wont be able to run anyways due to WF, local analysis at exec time, BTP, ... Dangerous attacks usually never come from known hashes&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We do check files when the users is going to execute because then, is when the file can turn into a real threat and at this time we discover and stop the unknown as well as the known threats. And at that time we will stop them, and report it to alerts and incidents. Additionally you have a number of actions to do with files afterwards treating them as malware and delete them, quarantine them, allow them if they happen to be benign even the initial behavior was triggered as malicious...&amp;nbsp;&lt;/P&gt;&lt;P&gt;Be confident that with CXDR you will be protected from the known and even much better "from the unknown".&amp;nbsp;&lt;/P&gt;&lt;P&gt;These detections that you showed that were not discovered by CXDR is because the were not scanned by CXDR ?&amp;nbsp; or nobody tried to execute them.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Realize that even if you try a file that goes unknown from a hash check&amp;nbsp; in any AV (CXDR included) when you try to execute it we will analyse at pre-execution and execution time, putting it in context with parent and child processes it might try to create. And whenever we detect something suspicious we will stop/block it and report it on the form of alerts and group them (the related alerts) within incidents for further investigation and incident response.&lt;/P&gt;&lt;P&gt;KR,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luis&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Mar 2022 14:55:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/474439#M1721</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2022-03-19T14:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex xdr did not detect malware, what good is it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/477736#M1821</link>
      <description>&lt;P&gt;How would you setup CXDR to treat PUA as malwares?&lt;/P&gt;</description>
      <pubDate>Sat, 02 Apr 2022 20:01:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/477736#M1821</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2022-04-02T20:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex xdr did not detect malware, what good is it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/477756#M1824</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163390"&gt;@KanwarSingh01&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im just thinking fast and on the fly you might think of doing several things:&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;adding hashses to block list&lt;/LI&gt;&lt;LI&gt;tweaking WF verdicts to malicious if they are triggered to bening or unknown. You might even ask for suex through TAC cases if needed&lt;/LI&gt;&lt;LI&gt;If you know or suspect that they are usually dropped at user download folders, ban the execution from that folder (you might even do such with AD GPO)&lt;/LI&gt;&lt;LI&gt;Treat unknown as malware&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Check howtos here:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/endpoint-security-profiles/add-malware-security-profile.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/endpoint-security-profiles/add-malware-security-profile.html&lt;/A&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Sun, 03 Apr 2022 14:36:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/477756#M1824</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2022-04-03T14:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex xdr did not detect malware, what good is it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/477786#M1827</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163390"&gt;@KanwarSingh01&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alot of the PUA are considered grayware, there is an option on malware profile&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-profiles/add-malware-security-profile" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-profiles/add-malware-security-profile&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV&gt;Grayware&lt;/DIV&gt;—The sample does not pose a direct security threat, but might display otherwise obtrusive behavior. Grayware typically includes adware, spyware, and Browser Helper Objects (BHOs).&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190764"&gt;@eluis&lt;/a&gt;&amp;nbsp;mentioned, you can manually add the hashes to the block list.&lt;/P&gt;&lt;P&gt;Also you can do restriction profile as an option&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-profiles/add-restrictions-profile" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-profiles/add-restrictions-profile&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 04:05:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/477786#M1827</guid>
      <dc:creator>jcandelaria</dc:creator>
      <dc:date>2022-04-04T04:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex xdr did not detect malware, what good is it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/477802#M1829</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190764"&gt;@eluis&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/174003"&gt;@jcandelaria&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I though there might be some other way which i might be missing out for catching PUAs, hence the question. I think I am fine with the discussion, PUAs are never ending topics i.e. every SecOps guy has its own terminology for PUAs and they are not threat to orgs directly and also can never be full proof prevention in stopping all PUAs.&lt;/P&gt;&lt;P&gt;Good example: NSSM.exe (A service wrapper on Windows) is used for service installation of services like ELK on windows but can also be used in an attack for persistence.&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190764"&gt;@eluis&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/174003"&gt;@jcandelaria&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 04:48:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/477802#M1829</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2022-04-04T04:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex xdr did not detect malware, what good is it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/477915#M1832</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163390"&gt;@KanwarSingh01&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;another action to take relatedf to this PUAs is to clarify in your securiry policies internally what your organization considers a PUA, what is allowed and what is not. After that you can totally prohibit in profiles or through hashes added to block-list the apps that you consider in your internal policies as unwanted.&lt;/P&gt;&lt;P&gt;KR,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luis&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 10:16:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-did-not-detect-malware-what-good-is-it/m-p/477915#M1832</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2022-04-04T10:16:48Z</dc:date>
    </item>
  </channel>
</rss>

