<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: A question from the Alert Tuning Operations Webinar: Signing level in a child process in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-alert-tuning-operations-webinar-signing/m-p/505721#M2266</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/216120"&gt;@rtsedaka&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is Google Chrome Helper being blocked by XDR? if yes, which alert type? Local Analysis? Wildfire? Suspicious Process Creation?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jun 2022 09:08:44 GMT</pubDate>
    <dc:creator>fmoixsante</dc:creator>
    <dc:date>2022-06-23T09:08:44Z</dc:date>
    <item>
      <title>A question from the Alert Tuning Operations Webinar: Signing level in a child process</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-alert-tuning-operations-webinar-signing/m-p/505718#M2265</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We have a mac-device on which even a reinstalled chrome creates child processes (Google Chrome Helper) that are apparently below the signing level of the parent process. Their signatures seem to be valid. Seems like whitelisting the hash of the initiator is not the best idea. What would be the best process if a child's process is blocked due to the signing level of the parent?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 09:05:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-alert-tuning-operations-webinar-signing/m-p/505718#M2265</guid>
      <dc:creator>rtsedaka</dc:creator>
      <dc:date>2022-06-23T09:05:21Z</dc:date>
    </item>
    <item>
      <title>Re: A question from the Alert Tuning Operations Webinar: Signing level in a child process</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-alert-tuning-operations-webinar-signing/m-p/505721#M2266</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/216120"&gt;@rtsedaka&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is Google Chrome Helper being blocked by XDR? if yes, which alert type? Local Analysis? Wildfire? Suspicious Process Creation?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 09:08:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-alert-tuning-operations-webinar-signing/m-p/505721#M2266</guid>
      <dc:creator>fmoixsante</dc:creator>
      <dc:date>2022-06-23T09:08:44Z</dc:date>
    </item>
  </channel>
</rss>

