<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Where to get more information on &amp;quot;Behavioral threat detected (rule: create_renamed_script_engine_by_hash)&amp;quot; in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/where-to-get-more-information-on-quot-behavioral-threat-detected/m-p/482038#M1908</link>
    <description>&lt;P&gt;Hello Cortex users, wondering if anyone has seen this before?&amp;nbsp; We are getting a single host flagged with a large amount of "&lt;SPAN&gt;Behavioral threat detected (rule: create_renamed_script_engine_by_hash)" but when we investigate in Cortex XDR there is almost no information to go on.&amp;nbsp; The process shows ::1 for the value, no path, command, PID, TID, MD5.&amp;nbsp; Signature is unavailable. It's not giving us much to go on.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We looked at the host and didn't see anything in particular in the System/Application/Security event logs, nothing repeating at the times the events fires.&amp;nbsp; We were seeing it up to every about 5 minutes last night.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any guidance on what we can zero in on, I can't find any other references to this specific alert.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Apr 2022 16:42:44 GMT</pubDate>
    <dc:creator>SGarringer</dc:creator>
    <dc:date>2022-04-22T16:42:44Z</dc:date>
    <item>
      <title>Where to get more information on "Behavioral threat detected (rule: create_renamed_script_engine_by_hash)"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/where-to-get-more-information-on-quot-behavioral-threat-detected/m-p/482038#M1908</link>
      <description>&lt;P&gt;Hello Cortex users, wondering if anyone has seen this before?&amp;nbsp; We are getting a single host flagged with a large amount of "&lt;SPAN&gt;Behavioral threat detected (rule: create_renamed_script_engine_by_hash)" but when we investigate in Cortex XDR there is almost no information to go on.&amp;nbsp; The process shows ::1 for the value, no path, command, PID, TID, MD5.&amp;nbsp; Signature is unavailable. It's not giving us much to go on.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We looked at the host and didn't see anything in particular in the System/Application/Security event logs, nothing repeating at the times the events fires.&amp;nbsp; We were seeing it up to every about 5 minutes last night.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any guidance on what we can zero in on, I can't find any other references to this specific alert.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 16:42:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/where-to-get-more-information-on-quot-behavioral-threat-detected/m-p/482038#M1908</guid>
      <dc:creator>SGarringer</dc:creator>
      <dc:date>2022-04-22T16:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: Where to get more information on "Behavioral threat detected (rule: create_renamed_script_engine_by_hash)"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/where-to-get-more-information-on-quot-behavioral-threat-detected/m-p/482163#M1909</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/217244"&gt;@SGarringer&lt;/a&gt;&amp;nbsp;What cortex licenses version are you using? Seems Prevent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you take a look at the prevention folder in c:\ProgramData\Cyvera\Prevention Folders and look into the prevention alert which is generated around that time, this will give a little bit of more information for your investigation around the alert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to me this alert triggers when you have a hash of a process which is similar to wscript.exe, cscript.exe, cmd.exe or powershell.exe (scripting engine process) but the "&lt;STRONG&gt;process name"&lt;/STRONG&gt; is not a scripting engine process but has a &lt;STRONG&gt;same hash&lt;/STRONG&gt; value. When triggered by a suspicious parent process as setup in PA Cortex defined rule set.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hash of cmd.exe == hash of blahh.exe (Trigger Rule.) if the parent is x, y or z.exe (Something like this.)&lt;/P&gt;&lt;P&gt;List of scripting engine:&lt;/P&gt;&lt;P&gt;&lt;A href="https://attack.mitre.org/techniques/T1059" target="_blank"&gt;https://attack.mitre.org/techniques/T1059&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You will come to know more about the story when you take a look at the prevention alert data in the folder which i have mentioned.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Apr 2022 01:08:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/where-to-get-more-information-on-quot-behavioral-threat-detected/m-p/482163#M1909</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2022-04-24T01:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: Where to get more information on "Behavioral threat detected (rule: create_renamed_script_engine_by_hash)"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/where-to-get-more-information-on-quot-behavioral-threat-detected/m-p/482401#M1914</link>
      <description>&lt;P&gt;This was exactly the information we needed.&amp;nbsp; In this case it was an SCCM folder that we needed to exclude as per best practices from Microsoft.&amp;nbsp; We've done that now and hopefully that will resolve the issue.&amp;nbsp; It's unfortunate that the file information doesn't flow back into Cortex XDR for easy viewing and instead we have to pull these files.&amp;nbsp; I'm new to supporting Cortex XDR Protect so that's great to know about the additional info in those files.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 19:40:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/where-to-get-more-information-on-quot-behavioral-threat-detected/m-p/482401#M1914</guid>
      <dc:creator>SGarringer</dc:creator>
      <dc:date>2022-04-25T19:40:27Z</dc:date>
    </item>
  </channel>
</rss>

