<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Coretex XDR alert/incidents for wildfire test file in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/coretex-xdr-alert-incidents-for-wildfire-test-file/m-p/336404#M187</link>
    <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the wildfire test file generate a alert/incident which can be seen XRD console ?&lt;/P&gt;&lt;P&gt;I have a XDR agent connected to cloud. The wildfire test sample in prevented and i can see it in events of XDR agent. I cannot see this in XDR console neither in incident nor alert table. Does this expected behaviour ?.&lt;/P&gt;&lt;P&gt;Also i noticed that one of the prevention (not the test file but other .exe) is also not visible in portal. I hope each security events in agent should create at least one alert in console.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Jul 2020 06:06:28 GMT</pubDate>
    <dc:creator>Abdul_Razaq</dc:creator>
    <dc:date>2020-07-02T06:06:28Z</dc:date>
    <item>
      <title>Coretex XDR alert/incidents for wildfire test file</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/coretex-xdr-alert-incidents-for-wildfire-test-file/m-p/336404#M187</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the wildfire test file generate a alert/incident which can be seen XRD console ?&lt;/P&gt;&lt;P&gt;I have a XDR agent connected to cloud. The wildfire test sample in prevented and i can see it in events of XDR agent. I cannot see this in XDR console neither in incident nor alert table. Does this expected behaviour ?.&lt;/P&gt;&lt;P&gt;Also i noticed that one of the prevention (not the test file but other .exe) is also not visible in portal. I hope each security events in agent should create at least one alert in console.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 06:06:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/coretex-xdr-alert-incidents-for-wildfire-test-file/m-p/336404#M187</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2020-07-02T06:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: Coretex XDR alert/incidents for wildfire test file</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/coretex-xdr-alert-incidents-for-wildfire-test-file/m-p/338678#M195</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/101029"&gt;@Abdul_Razaq&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The test PE should not create an incident, but it should create an alert even though it is prevented.&amp;nbsp; I have tested and verified this in the past.&amp;nbsp; For the policy rule applied to the machine what does the malware profile specify instruction-wise?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 14:25:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/coretex-xdr-alert-incidents-for-wildfire-test-file/m-p/338678#M195</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-07-15T14:25:28Z</dc:date>
    </item>
  </channel>
</rss>

