<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Securing old web server IIS6 in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/securing-old-web-server-iis6/m-p/481218#M1893</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/65550"&gt;@Fido&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I agree with what &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163390"&gt;@KanwarSingh01&lt;/a&gt;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;suggests.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could develop some use cases and implement them through your own correlation rules, BIOCs, .... You could even ingest logs from your&amp;nbsp; &lt;SPAN&gt;IIS6.1&amp;nbsp;&lt;/SPAN&gt;with Cortex XDR Collectors or Filebeat, parse them on XDR and from there you can be creative on what are your defensive goals (from which threats do you want to protect your web server)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luis&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Apr 2022 06:12:34 GMT</pubDate>
    <dc:creator>eluis</dc:creator>
    <dc:date>2022-04-20T06:12:34Z</dc:date>
    <item>
      <title>Securing old web server IIS6</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/securing-old-web-server-iis6/m-p/480700#M1876</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are solving a case of an IIS6.1 vulnerability on an old Windows 2008 R2 SP1 system. Microsoft no longer has support for Windows update. The customer cannot migrate to the newer system yet.&lt;BR /&gt;Would Cortex XDR be able to secure IIS v6.1 web server vulnerabilities?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 09:35:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/securing-old-web-server-iis6/m-p/480700#M1876</guid>
      <dc:creator>Fido</dc:creator>
      <dc:date>2022-04-18T09:35:11Z</dc:date>
    </item>
    <item>
      <title>Re: Securing old web server IIS6</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/securing-old-web-server-iis6/m-p/481187#M1892</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/65550"&gt;@Fido&lt;/a&gt;&amp;nbsp;Practically I think you should take defense in depth approach here and not just rely on Cortex XDR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; Ring fence server i.e. make sure you lock it down into its own network.&lt;/P&gt;&lt;P&gt;&amp;gt; Monitor logons and expose what is required to the internet if a public facing internet.&lt;/P&gt;&lt;P&gt;&amp;gt; Enable IPS system for network traffic. (Test first by enabling IDS before IPS)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apart from above, you should be able to get prevention on post exploitation activity with Cortex for un-known threats and as well for known threat.&lt;/P&gt;&lt;P&gt;Example: A command interpreter process such as cmd.exe or powershell.exe spawn from w3wp.exe&lt;/P&gt;&lt;P&gt;You can also create your own detection which can help you detect threats related to your environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What version of Cortex XDR are you looking to install?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 00:57:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/securing-old-web-server-iis6/m-p/481187#M1892</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2022-04-20T00:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Securing old web server IIS6</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/securing-old-web-server-iis6/m-p/481218#M1893</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/65550"&gt;@Fido&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I agree with what &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163390"&gt;@KanwarSingh01&lt;/a&gt;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;suggests.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could develop some use cases and implement them through your own correlation rules, BIOCs, .... You could even ingest logs from your&amp;nbsp; &lt;SPAN&gt;IIS6.1&amp;nbsp;&lt;/SPAN&gt;with Cortex XDR Collectors or Filebeat, parse them on XDR and from there you can be creative on what are your defensive goals (from which threats do you want to protect your web server)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luis&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 06:12:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/securing-old-web-server-iis6/m-p/481218#M1893</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2022-04-20T06:12:34Z</dc:date>
    </item>
    <item>
      <title>Re: Securing old web server IIS6</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/securing-old-web-server-iis6/m-p/481221#M1894</link>
      <description>&lt;P&gt;Thanks guys for the feedback.&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163390" target="_blank"&gt;@KanwarSingh01&lt;/A&gt;&amp;nbsp;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;We want to install Cortex XDR 7.7&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 07:22:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/securing-old-web-server-iis6/m-p/481221#M1894</guid>
      <dc:creator>Fido</dc:creator>
      <dc:date>2022-04-20T07:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: Securing old web server IIS6</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/securing-old-web-server-iis6/m-p/481786#M1901</link>
      <description>&lt;P&gt;You should be good here.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 22:37:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/securing-old-web-server-iis6/m-p/481786#M1901</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2022-04-21T22:37:20Z</dc:date>
    </item>
  </channel>
</rss>

