<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex does not block Windows binaries in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-does-not-block-windows-binaries/m-p/495153#M2059</link>
    <description>&lt;P&gt;To mitigate cve-2022-30190 i wanted to add the file hashes of the msdt.exe binary to the blocklist; but with no effect until now.&lt;BR /&gt;The hashes occure in the logfile of the agent below hashcontrol as enabled, but verdict has a value "0".&lt;BR /&gt;Is it possible, that windows binaries are excluded from blocking by default?&lt;BR /&gt;i decided to block the binary for mitigation, because it's a minimal-invasiv approach, which can be reverted quickly if the issue is patched.&lt;/P&gt;</description>
    <pubDate>Tue, 31 May 2022 09:12:51 GMT</pubDate>
    <dc:creator>RonaldWeiss</dc:creator>
    <dc:date>2022-05-31T09:12:51Z</dc:date>
    <item>
      <title>Cortex does not block Windows binaries</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-does-not-block-windows-binaries/m-p/495153#M2059</link>
      <description>&lt;P&gt;To mitigate cve-2022-30190 i wanted to add the file hashes of the msdt.exe binary to the blocklist; but with no effect until now.&lt;BR /&gt;The hashes occure in the logfile of the agent below hashcontrol as enabled, but verdict has a value "0".&lt;BR /&gt;Is it possible, that windows binaries are excluded from blocking by default?&lt;BR /&gt;i decided to block the binary for mitigation, because it's a minimal-invasiv approach, which can be reverted quickly if the issue is patched.&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 09:12:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-does-not-block-windows-binaries/m-p/495153#M2059</guid>
      <dc:creator>RonaldWeiss</dc:creator>
      <dc:date>2022-05-31T09:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex does not block Windows binaries</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-does-not-block-windows-binaries/m-p/496030#M2072</link>
      <description>&lt;P&gt;Te sugiero sigas los siguientes pasos publicados por Microsoft hasta que tengas una respuesta por parted e Cortex Palo Alto.&lt;/P&gt;&lt;P&gt;&lt;A href="https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/" target="_blank"&gt;https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 17:59:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-does-not-block-windows-binaries/m-p/496030#M2072</guid>
      <dc:creator>evillegas1992</dc:creator>
      <dc:date>2022-05-31T17:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex does not block Windows binaries</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-does-not-block-windows-binaries/m-p/496690#M2077</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;as Luc mentioned here (&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/m-p/496106/highlight/true#M2073" target="_self"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/m-p/496106/highlight/true#M2073&lt;/A&gt;&amp;nbsp;) the use of custom prevention rules&amp;nbsp; with the BIOC works lika a charm here.&lt;/P&gt;&lt;P&gt;So, this will be my solution until PA or Microsoft deliver a proper one. (Which, for PA, might be a BIOC, too &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; )&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 06:59:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-does-not-block-windows-binaries/m-p/496690#M2077</guid>
      <dc:creator>RonaldWeiss</dc:creator>
      <dc:date>2022-06-01T06:59:54Z</dc:date>
    </item>
  </channel>
</rss>

