<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does the Cortex XDR Agent work in Windows Safe Mode? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-the-cortex-xdr-agent-work-in-windows-safe-mode/m-p/511561#M2522</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi Rob,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The Cortex XDR Agent is currently not designed to function with Windows Safe Mode.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The following tests were performed on a Windows 10 endpoint that was booted into Windows Safe Mode with the Cortex XDR agent installed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mfakhouri_0-1660222902982.png" style="width: 438px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43107iBD8FBA7011CBF572/image-dimensions/438x325/is-moderation-mode/true?v=v2" width="438" height="325" role="button" title="mfakhouri_0-1660222902982.png" alt="mfakhouri_0-1660222902982.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Figure 1: The tray application was not open upon the Safe Mode boot. After navigating to and running the tray executable file in C:\Project Files\ Palo Alto Networks\Traps, the menu displays that Advanced Endpoint Protection is disabled and that connection to the service is not available.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mfakhouri_1-1660222902986.png" style="width: 457px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43108i94EA9A11FCC03B1A/image-dimensions/457x309/is-moderation-mode/true?v=v2" width="457" height="309" role="button" title="mfakhouri_1-1660222902986.png" alt="mfakhouri_1-1660222902986.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Figure 2: Cyserver.exe is the main process executable responsible for starting the Cortex XDR Service as of agent release 7.1 (see references for more information). After attempting to start the “cyserver” service from the command line with net start, there is a system error reading that “This service cannot be started in Safe Mode”.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mfakhouri_2-1660222902944.png" style="width: 480px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43106i50CCF9B6647C9B38/image-dimensions/480x337/is-moderation-mode/true?v=v2" width="480" height="337" role="button" title="mfakhouri_2-1660222902944.png" alt="mfakhouri_2-1660222902944.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Figure 3: Cytool is a command line interface tool that offers management with the components of Cortex XDR when operating in the directory C:\Project Files\ Palo Alto Networks\Traps. “cytool enum” enumerates protected processes (as seen in the cytool documentation listed below), but in this case the system cannot find the file specified to execute the command.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Since this test was done on a Windows 10 endpoint in particular, I would be interested to hear what Windows version you had in mind for the Windows Safe Mode Boot functionality.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Reference:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cyserver.exe process details&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-1/cortex-xdr-agent-release-notes/cortex-xdr-agent-release-information/changes-to-default-behavior#id1787F023048" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-1/cortex-xdr-agent-release-notes/cortex-xdr-agent-release-information/changes-to-default-behavior#id1787F023048&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cytool functionality on Windows endpoints&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/5-0/cortex-xdr-agent-admin/traps-agent-for-windows/troubleshoot-traps-for-windows/cytool" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/5-0/cortex-xdr-agent-admin/traps-agent-for-windows/troubleshoot-traps-for-windows/cytool&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Aug 2022 13:05:07 GMT</pubDate>
    <dc:creator>mfakhouri</dc:creator>
    <dc:date>2022-08-11T13:05:07Z</dc:date>
    <item>
      <title>Does the Cortex XDR Agent work in Windows Safe Mode?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-the-cortex-xdr-agent-work-in-windows-safe-mode/m-p/511460#M2509</link>
      <description>&lt;P&gt;Hello dear Community,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does the Cortex XDR Agent work in Windows Safe Mode?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://attack.mitre.org/techniques/T1562/009/" target="_blank"&gt;https://attack.mitre.org/techniques/T1562/009/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RFeyertag_0-1660147159121.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43091iEE30D2CFB5FE00CE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="RFeyertag_0-1660147159121.png" alt="RFeyertag_0-1660147159121.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 16:00:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-the-cortex-xdr-agent-work-in-windows-safe-mode/m-p/511460#M2509</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-08-10T16:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: Does the Cortex XDR Agent work in Windows Safe Mode?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-the-cortex-xdr-agent-work-in-windows-safe-mode/m-p/511561#M2522</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Rob,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The Cortex XDR Agent is currently not designed to function with Windows Safe Mode.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The following tests were performed on a Windows 10 endpoint that was booted into Windows Safe Mode with the Cortex XDR agent installed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mfakhouri_0-1660222902982.png" style="width: 438px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43107iBD8FBA7011CBF572/image-dimensions/438x325/is-moderation-mode/true?v=v2" width="438" height="325" role="button" title="mfakhouri_0-1660222902982.png" alt="mfakhouri_0-1660222902982.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Figure 1: The tray application was not open upon the Safe Mode boot. After navigating to and running the tray executable file in C:\Project Files\ Palo Alto Networks\Traps, the menu displays that Advanced Endpoint Protection is disabled and that connection to the service is not available.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mfakhouri_1-1660222902986.png" style="width: 457px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43108i94EA9A11FCC03B1A/image-dimensions/457x309/is-moderation-mode/true?v=v2" width="457" height="309" role="button" title="mfakhouri_1-1660222902986.png" alt="mfakhouri_1-1660222902986.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Figure 2: Cyserver.exe is the main process executable responsible for starting the Cortex XDR Service as of agent release 7.1 (see references for more information). After attempting to start the “cyserver” service from the command line with net start, there is a system error reading that “This service cannot be started in Safe Mode”.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mfakhouri_2-1660222902944.png" style="width: 480px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43106i50CCF9B6647C9B38/image-dimensions/480x337/is-moderation-mode/true?v=v2" width="480" height="337" role="button" title="mfakhouri_2-1660222902944.png" alt="mfakhouri_2-1660222902944.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Figure 3: Cytool is a command line interface tool that offers management with the components of Cortex XDR when operating in the directory C:\Project Files\ Palo Alto Networks\Traps. “cytool enum” enumerates protected processes (as seen in the cytool documentation listed below), but in this case the system cannot find the file specified to execute the command.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Since this test was done on a Windows 10 endpoint in particular, I would be interested to hear what Windows version you had in mind for the Windows Safe Mode Boot functionality.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Reference:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cyserver.exe process details&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-1/cortex-xdr-agent-release-notes/cortex-xdr-agent-release-information/changes-to-default-behavior#id1787F023048" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-1/cortex-xdr-agent-release-notes/cortex-xdr-agent-release-information/changes-to-default-behavior#id1787F023048&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cytool functionality on Windows endpoints&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/5-0/cortex-xdr-agent-admin/traps-agent-for-windows/troubleshoot-traps-for-windows/cytool" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/5-0/cortex-xdr-agent-admin/traps-agent-for-windows/troubleshoot-traps-for-windows/cytool&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 13:05:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-the-cortex-xdr-agent-work-in-windows-safe-mode/m-p/511561#M2522</guid>
      <dc:creator>mfakhouri</dc:creator>
      <dc:date>2022-08-11T13:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: Does the Cortex XDR Agent work in Windows Safe Mode?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-the-cortex-xdr-agent-work-in-windows-safe-mode/m-p/511567#M2523</link>
      <description>&lt;P&gt;Exactly this answers my question, thank you very much!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/8014"&gt;@PA&lt;/a&gt;: will there be a version which works in safe mode with networking?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 14:24:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-the-cortex-xdr-agent-work-in-windows-safe-mode/m-p/511567#M2523</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-08-11T14:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: Does the Cortex XDR Agent work in Windows Safe Mode?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-the-cortex-xdr-agent-work-in-windows-safe-mode/m-p/511583#M2525</link>
      <description>&lt;P&gt;Hi RFeyertag,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please reach out to your SE/account team for discussions on product feedback and roadmap.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 17:13:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-the-cortex-xdr-agent-work-in-windows-safe-mode/m-p/511583#M2525</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2022-08-11T17:13:04Z</dc:date>
    </item>
  </channel>
</rss>

