<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic A question from the Alert Tuning Operations Webinar: Signing level in a child process in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-alert-tuning-operations-webinar-signing/m-p/505718#M2265</link>
    <description>&lt;P&gt;&lt;SPAN&gt;We have a mac-device on which even a reinstalled chrome creates child processes (Google Chrome Helper) that are apparently below the signing level of the parent process. Their signatures seem to be valid. Seems like whitelisting the hash of the initiator is not the best idea. What would be the best process if a child's process is blocked due to the signing level of the parent?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jun 2022 09:05:21 GMT</pubDate>
    <dc:creator>rtsedaka</dc:creator>
    <dc:date>2022-06-23T09:05:21Z</dc:date>
    <item>
      <title>A question from the Alert Tuning Operations Webinar: Signing level in a child process</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-alert-tuning-operations-webinar-signing/m-p/505718#M2265</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We have a mac-device on which even a reinstalled chrome creates child processes (Google Chrome Helper) that are apparently below the signing level of the parent process. Their signatures seem to be valid. Seems like whitelisting the hash of the initiator is not the best idea. What would be the best process if a child's process is blocked due to the signing level of the parent?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 09:05:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-alert-tuning-operations-webinar-signing/m-p/505718#M2265</guid>
      <dc:creator>rtsedaka</dc:creator>
      <dc:date>2022-06-23T09:05:21Z</dc:date>
    </item>
    <item>
      <title>Re: A question from the Alert Tuning Operations Webinar: Signing level in a child process</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-alert-tuning-operations-webinar-signing/m-p/505721#M2266</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/216120"&gt;@rtsedaka&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is Google Chrome Helper being blocked by XDR? if yes, which alert type? Local Analysis? Wildfire? Suspicious Process Creation?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 09:08:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-alert-tuning-operations-webinar-signing/m-p/505721#M2266</guid>
      <dc:creator>fmoixsante</dc:creator>
      <dc:date>2022-06-23T09:08:44Z</dc:date>
    </item>
  </channel>
</rss>

