<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR has Blocked a Malicious Activity but No Program Listed in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486175#M1954</link>
    <description>&lt;P&gt;Attached images show the pop-up that is going around our network this morning.&amp;nbsp; Unlike before where it would list the program Cortex blocks there is nothing there and is pointing at Microsoft for the cause.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this a false positive?&amp;nbsp; A windows service is triggering Cortex to block the behavioral threat?&lt;/P&gt;</description>
    <pubDate>Tue, 10 May 2022 17:08:50 GMT</pubDate>
    <dc:creator>mixzawa</dc:creator>
    <dc:date>2022-05-10T17:08:50Z</dc:date>
    <item>
      <title>Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486175#M1954</link>
      <description>&lt;P&gt;Attached images show the pop-up that is going around our network this morning.&amp;nbsp; Unlike before where it would list the program Cortex blocks there is nothing there and is pointing at Microsoft for the cause.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this a false positive?&amp;nbsp; A windows service is triggering Cortex to block the behavioral threat?&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 17:08:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486175#M1954</guid>
      <dc:creator>mixzawa</dc:creator>
      <dc:date>2022-05-10T17:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486185#M1955</link>
      <description>&lt;P&gt;We're getting the same type alert this morning on all our endpoints.&amp;nbsp; We haven't determined what is causing it though.&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 17:25:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486185#M1955</guid>
      <dc:creator>mdb1998</dc:creator>
      <dc:date>2022-05-10T17:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486194#M1956</link>
      <description>&lt;P&gt;We are seeing Cortex Behavioral Threat High Blocks related to Microsoft.&amp;nbsp; Pretty much all end points.&amp;nbsp;&amp;nbsp; smss.exe .. a MSFT signed file is identified.&amp;nbsp;&amp;nbsp; Unclear what is the precise cause.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 17:42:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486194#M1956</guid>
      <dc:creator>KMcKenna</dc:creator>
      <dc:date>2022-05-10T17:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486195#M1957</link>
      <description>&lt;P&gt;Minor update my home office PC (Windows 100 Pro) now got the notification from XDR while at work we use Windows 10 Pro.&amp;nbsp; Can never have a quiet day off can I?&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 17:46:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486195#M1957</guid>
      <dc:creator>mixzawa</dc:creator>
      <dc:date>2022-05-10T17:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486200#M1958</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;We're seeing the same here as well. End users are shown no application name, but digging through the incidents in the console shows that it's killing of Smss.exe, which is the System Center Configuration Manager agent.&lt;BR /&gt;&lt;BR /&gt;All endpoints generating alerts are running 7.7.0.60725 here.&lt;BR /&gt;&lt;BR /&gt;Looking through the timeline there seems to be no evidence of foul play.&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 18:09:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486200#M1958</guid>
      <dc:creator>arvesynd</dc:creator>
      <dc:date>2022-05-10T18:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486203#M1959</link>
      <description>&lt;P&gt;We are on 7.7.0 as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the comment&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 18:12:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486203#M1959</guid>
      <dc:creator>KMcKenna</dc:creator>
      <dc:date>2022-05-10T18:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486204#M1960</link>
      <description>&lt;P&gt;This alert just trigged on my personal device when updating to content version 500-90199.&lt;BR /&gt;Sooo... rollback, please?&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 18:14:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486204#M1960</guid>
      <dc:creator>arvesynd</dc:creator>
      <dc:date>2022-05-10T18:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486207#M1961</link>
      <description>&lt;P&gt;We have a Support ticket opened (High Severity) and also are working with an inside (Palo) engineer associated with our Sales team.&amp;nbsp; So hopefully we will learn more soon.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 18:20:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486207#M1961</guid>
      <dc:creator>KMcKenna</dc:creator>
      <dc:date>2022-05-10T18:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486209#M1962</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36791"&gt;@KMcKenna&lt;/a&gt;&amp;nbsp;Please let us know if they provide a workaround or a fix for the issue.&lt;/P&gt;&lt;P&gt;Fingers crossed the update either get fixed or pulled tonight, so I won't have to deal with this when each endpoint boots tomorrow.&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 18:48:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486209#M1962</guid>
      <dc:creator>arvesynd</dc:creator>
      <dc:date>2022-05-10T18:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486210#M1963</link>
      <description>&lt;P&gt;Yes, absolutely.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For reference, if anyone else opens a case, our Case # is 02191931.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The rule triggering the alert is:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Behavioral threat detected (rule: other.malware_gen_task.105)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 18:52:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486210#M1963</guid>
      <dc:creator>KMcKenna</dc:creator>
      <dc:date>2022-05-10T18:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486214#M1964</link>
      <description>&lt;P&gt;Getting this too. It occurs after the latest content &amp;amp; policy update. I can manually trigger it but clicking check-in now button, so its like the process that applies the policy update is triggering itself lol.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can verify this in the endpoint log on portal, it triggers same time as the policy&lt;/P&gt;&lt;P&gt;update.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Support case logged also:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;CASE #:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;02191983&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="XDR event timestamps.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40938i638E08833203B3A1/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="XDR event timestamps.png" alt="XDR event timestamps.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policy Update Timestamps.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40940i5E413EEA92E58243/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Policy Update Timestamps.png" alt="Policy Update Timestamps.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 19:01:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486214#M1964</guid>
      <dc:creator>adminBandE</dc:creator>
      <dc:date>2022-05-10T19:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486218#M1965</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59013"&gt;@adminBandE&lt;/a&gt;&amp;nbsp;&amp;nbsp; I also clicked Check In Now on a completely isolated host (off site).&amp;nbsp;&amp;nbsp; Had same response as you in that the Alert triggered.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will add that to our support case.&amp;nbsp; Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 19:21:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486218#M1965</guid>
      <dc:creator>KMcKenna</dc:creator>
      <dc:date>2022-05-10T19:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486219#M1966</link>
      <description>&lt;P&gt;Update from my Case:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;From the case description, I understand that you are receiving BTP alerts for smss.exe for the rule other.malware_gen_task.105&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;I would like to inform you that it is a false positive BTP alert and multiple customers where reported the same. We are working on the fix and will update you as soon as available.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;As a workaround please create an alert exception for now reference.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just created the (temporary) exception, lets see if it takes effect!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: It does work. Apply the alert exception from the incident under alerts &amp;amp; insights, right-click the alert and select manage alert - create alert exception.&amp;nbsp; It will then appear under your global BTP rules.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 19:34:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486219#M1966</guid>
      <dc:creator>adminBandE</dc:creator>
      <dc:date>2022-05-10T19:34:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486220#M1967</link>
      <description>&lt;P&gt;Hoping for all of us as user calls about will get very old very fast.&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 19:33:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486220#M1967</guid>
      <dc:creator>mixzawa</dc:creator>
      <dc:date>2022-05-10T19:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486221#M1968</link>
      <description>&lt;P&gt;We are being told this is a False Positive and the Palo Support team is working on it.&amp;nbsp;&amp;nbsp; They say to create an exclusion in the meantime.&amp;nbsp; Some general info on doing that...&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/exceptions-security-profiles/add-exceptions-profile" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/exceptions-security-profiles/add-exceptions-profile&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a general Docs page.&amp;nbsp; So if you are not familiar with doing this, you may need more info.&amp;nbsp;&amp;nbsp; This is linked info not specific to this alert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's all I have at the moment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 19:39:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486221#M1968</guid>
      <dc:creator>KMcKenna</dc:creator>
      <dc:date>2022-05-10T19:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486236#M1969</link>
      <description>&lt;P&gt;Has there been any resolution yet? We are experiencing the same...&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 21:23:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486236#M1969</guid>
      <dc:creator>KPaschall</dc:creator>
      <dc:date>2022-05-10T21:23:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486238#M1970</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/158599"&gt;@KPaschall&lt;/a&gt;&amp;nbsp;&amp;nbsp; No specific fix other than Palo Alto has confirmed it is a False Positive and they are working on a solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the meantime they suggested creating an exception. However, when I created a Global Process Exception using 'smss.exe' as the process, we saw an alert about 7 or 8 minutes later on a remote laptop.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; So I am not sure if this exception is properly excluding what it needs to exclude.&amp;nbsp; As far as I can see in the alerts/incidents in the GUI.. there is no specific named 'process'.&amp;nbsp;&amp;nbsp; Just the file. So it might be working correctly, but I can't say for sure.&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 21:36:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486238#M1970</guid>
      <dc:creator>KMcKenna</dc:creator>
      <dc:date>2022-05-10T21:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486239#M1971</link>
      <description>&lt;P&gt;I also have this information to add from Palo Alto Networks support.... as of 5:30 PM US Eastern Daylight Time&lt;/P&gt;&lt;P&gt;----&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Content Update 510, will provide a fix [in] approximately 1 hour&lt;BR /&gt;- Content Update 500, will provide a fix [in] approximately 12 hours&lt;BR /&gt;&lt;BR /&gt;As a workaround please create an alert exception for now reference&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/exceptions-security-profiles/add-exceptions-profile" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/exceptions-security-profiles/add-exceptions-profile&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;To do this,&lt;BR /&gt;&lt;BR /&gt;1. Go to Incident Response &amp;gt; Incidents.&lt;BR /&gt;2. Right-click on the Behvaioral Threat Incident then click View Incident.&lt;BR /&gt;3. Under Alerts &amp;amp; Insights, look for the Behavior threat alert for the process.&lt;BR /&gt;4. Right-click on the alert then click Create alert exception.&lt;BR /&gt;5. Select the Exception Scope. You can assign it to a specific profile or set it to Global, then click Add.&lt;BR /&gt;&lt;BR /&gt;Once the fix is out, you can then remove the exception.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;---&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 21:41:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486239#M1971</guid>
      <dc:creator>KMcKenna</dc:creator>
      <dc:date>2022-05-10T21:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486240#M1972</link>
      <description>&lt;P&gt;One issue, as I mentioned previously, is that the process is not specifically named in the incident as far as I can see.&amp;nbsp; Only the file name of smss.exe.&amp;nbsp; So that file name is what I used as a process name.&amp;nbsp; Unclear if that is working since we did see one more alert 7 or 8 minutes after creating the Process Exception.&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 21:47:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486240#M1972</guid>
      <dc:creator>KMcKenna</dc:creator>
      <dc:date>2022-05-10T21:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR has Blocked a Malicious Activity but No Program Listed</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486370#M1973</link>
      <description>&lt;P&gt;An update from Palo Alto..&amp;nbsp; content version 510-90618 has been released and should address the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-K&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 14:34:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-has-blocked-a-malicious-activity-but-no-program/m-p/486370#M1973</guid>
      <dc:creator>KMcKenna</dc:creator>
      <dc:date>2022-05-11T14:34:38Z</dc:date>
    </item>
  </channel>
</rss>

