<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Behavioral Threat alerts for sdiagnhost.exe spawning cronhost.exe - false positive? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-alerts-for-sdiagnhost-exe-spawning-cronhost/m-p/511098#M2465</link>
    <description>&lt;P&gt;Hi, we are observing the same behaviour on different customers, some of them are behind the patch level but others are not.. We are concerned over Follina too, because for some of the alerts we had confirmation of unsolicited mail with attachments but, for other systems, there were no reason for an alert...&lt;/P&gt;</description>
    <pubDate>Fri, 05 Aug 2022 07:45:54 GMT</pubDate>
    <dc:creator>RobertoPastorino</dc:creator>
    <dc:date>2022-08-05T07:45:54Z</dc:date>
    <item>
      <title>Behavioral Threat alerts for sdiagnhost.exe spawning cronhost.exe - false positive?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-alerts-for-sdiagnhost-exe-spawning-cronhost/m-p/511083#M2464</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;
&lt;P&gt;Wondering if anyone else is seeing BT alerts for sdiagnhost.exe appearing over the last 24 hours? We have had similar things occur in the past due to over excited signature updates cause false positives.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This process is one that MSDT Follina uses but the servers it popping up on do not run any Office products running so confident it's not that, and mitigated MSDT issues back when they first hit the news.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 02:45:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-alerts-for-sdiagnhost-exe-spawning-cronhost/m-p/511083#M2464</guid>
      <dc:creator>adminBandE</dc:creator>
      <dc:date>2022-08-05T02:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: Behavioral Threat alerts for sdiagnhost.exe spawning cronhost.exe - false positive?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-alerts-for-sdiagnhost-exe-spawning-cronhost/m-p/511098#M2465</link>
      <description>&lt;P&gt;Hi, we are observing the same behaviour on different customers, some of them are behind the patch level but others are not.. We are concerned over Follina too, because for some of the alerts we had confirmation of unsolicited mail with attachments but, for other systems, there were no reason for an alert...&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 07:45:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-alerts-for-sdiagnhost-exe-spawning-cronhost/m-p/511098#M2465</guid>
      <dc:creator>RobertoPastorino</dc:creator>
      <dc:date>2022-08-05T07:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: Behavioral Threat alerts for sdiagnhost.exe spawning cronhost.exe - false positive?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-alerts-for-sdiagnhost-exe-spawning-cronhost/m-p/511102#M2466</link>
      <description>&lt;P&gt;We opened a ticket with the support, just in case.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 09:37:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-alerts-for-sdiagnhost-exe-spawning-cronhost/m-p/511102#M2466</guid>
      <dc:creator>RobertoPastorino</dc:creator>
      <dc:date>2022-08-05T09:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: Behavioral Threat alerts for sdiagnhost.exe spawning cronhost.exe - false positive?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-alerts-for-sdiagnhost-exe-spawning-cronhost/m-p/511105#M2467</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59013"&gt;@adminBandE&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/110751"&gt;@RobertoPastorino&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as Roberto has done, I would recommend to open a TAC support ticket under if you suspect that there is a weird behavior of BT protection. On top of that observe and investigate the incidents related to these alerts and do not discard them as a false positive until you are sure that it really is a false positive.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR,&amp;nbsp;&lt;BR /&gt;Luis&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 11:16:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-alerts-for-sdiagnhost-exe-spawning-cronhost/m-p/511105#M2467</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2022-08-05T11:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: Behavioral Threat alerts for sdiagnhost.exe spawning cronhost.exe - false positive?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-alerts-for-sdiagnhost-exe-spawning-cronhost/m-p/511137#M2475</link>
      <description>&lt;P&gt;Yes, we are seeing them as well. Microsoft released a patch for Follina about 2.5 weeks ago. I can only assume something they patched is triggering this event.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 17:50:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-alerts-for-sdiagnhost-exe-spawning-cronhost/m-p/511137#M2475</guid>
      <dc:creator>Dclark190</dc:creator>
      <dc:date>2022-08-05T17:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: Behavioral Threat alerts for sdiagnhost.exe spawning cronhost.exe - false positive?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-alerts-for-sdiagnhost-exe-spawning-cronhost/m-p/511194#M2484</link>
      <description>&lt;P&gt;Support replied confirming the issue as a false positive that will be addressed in a minor CU release due this week.&lt;/P&gt;
&lt;P&gt;In the meantime they suggested the creation of an alert exclusion for the CGO path and process for the affected agents only, to be removed after the CU is released.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Given the elusivity of the exploit, the fact that some bu are deaf on the necessity of quick patching and that for at least two endpoints there were a confirmed case of downloaded unsolicited email with office attachments, I will treat this case as a true positive, waiting for the CU to be released.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 07:24:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-alerts-for-sdiagnhost-exe-spawning-cronhost/m-p/511194#M2484</guid>
      <dc:creator>RobertoPastorino</dc:creator>
      <dc:date>2022-08-08T07:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: Behavioral Threat alerts for sdiagnhost.exe spawning cronhost.exe - false positive?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-alerts-for-sdiagnhost-exe-spawning-cronhost/m-p/511250#M2493</link>
      <description>&lt;P&gt;Thank you for sharing their response! We have not implemented a "bypass" we are seeing no negative effects of the blocking besides the alert messages. We will wait for them to patch it. Have a good monday!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 14:42:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-alerts-for-sdiagnhost-exe-spawning-cronhost/m-p/511250#M2493</guid>
      <dc:creator>Dclark190</dc:creator>
      <dc:date>2022-08-08T14:42:53Z</dc:date>
    </item>
    <item>
      <title>Re: Behavioral Threat alerts for sdiagnhost.exe spawning cronhost.exe - false positive?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-alerts-for-sdiagnhost-exe-spawning-cronhost/m-p/511361#M2505</link>
      <description>&lt;P&gt;We are also ignoring due to the risk of missing a legitimate alert. Not seeing this occur much in the environment and only on servers, thankfully.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 22:49:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-alerts-for-sdiagnhost-exe-spawning-cronhost/m-p/511361#M2505</guid>
      <dc:creator>adminBandE</dc:creator>
      <dc:date>2022-08-09T22:49:27Z</dc:date>
    </item>
  </channel>
</rss>

