<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR not detecting malicious files in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-not-detecting-malicious-files/m-p/512080#M2559</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/195524"&gt;@Anil_Racharla&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cortex XDR though does dormant file detection, but it is designed to be an execution based detection and prevention solution. Often malwares or malicious files are zipped and compressed with different folders or other files(like jpg files, zip files, etc.). Changing the form factor and entity of the file also changes the property and the hashing of the file. The actual zipped/modified file may not be malicious, but upon execution it opens up a new child executable which might be a malware altogether. The resulting causality chain is malicious and should be the one to be detected and prevented accordingly.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do check for file properties and criteria. Also, you might want to check the policy configuration of the endpoint agent you are testing the samples on.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Aug 2022 07:36:31 GMT</pubDate>
    <dc:creator>neelrohit</dc:creator>
    <dc:date>2022-08-17T07:36:31Z</dc:date>
    <item>
      <title>Cortex XDR not detecting malicious files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-not-detecting-malicious-files/m-p/501982#M2156</link>
      <description>&lt;P&gt;Hi ,&lt;BR /&gt;Why Cortex XDR is not detecting malicious files which are present in system.&lt;BR /&gt;for testing purpose I have downloaded a test malware also but it is not reflected after the malware scan.Can anyone please give clarity on this.&lt;BR /&gt;Does Cortex detects malicious files only when they are &amp;nbsp;executed ?&lt;BR /&gt;Does Cortex XDR don't detect files which are not executed and simply lied down in the system ? In case if we want know the unexecuted Malicious files and get the alert for the same, do we need to add any other features/licenses ?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 03:57:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-not-detecting-malicious-files/m-p/501982#M2156</guid>
      <dc:creator>Anil_Racharla</dc:creator>
      <dc:date>2022-06-09T03:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR not detecting malicious files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-not-detecting-malicious-files/m-p/505904#M2270</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/195524"&gt;@Anil_Racharla&lt;/a&gt;,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;1. &lt;/SPAN&gt;&lt;SPAN&gt;Cortex XDR’s default malware policy rules utilize both pre-execution and post-execution malware protection. WildFire is used for pre-execution and executes several checks:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;WF static analysis&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Machine learning&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Dynamic analysis&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Bare metal&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;The file will go to Local Analysis if there is no verdict to be found with WF. Cortex XDR post-execution malware prevention includes: behavior threat protection, anti-ransomware, password theft protection, and child process protection.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;2.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Cortex XDR malware scans check for dormant malware and differs from the protection leveraged during the malware execution. These scans can be done either manually or periodically with prevention profiles and do not require any additional features/licenses.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here is a relevant, high-level graphic illustrating &lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/analysis-and-protection-flow" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Cortex XDR file analysis&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pasted image 0.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41957iE9F464873082CD12/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pasted image 0.png" alt="pasted image 0.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Are you expecting dormant detection or a detonation that may have been missed by the Cortex XDR agent? Are you able to share any hash info for verification?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 22:17:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-not-detecting-malicious-files/m-p/505904#M2270</guid>
      <dc:creator>mfakhouri</dc:creator>
      <dc:date>2022-06-23T22:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR not detecting malicious files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-not-detecting-malicious-files/m-p/511805#M2544</link>
      <description>&lt;P&gt;thanks a lot ,&lt;BR /&gt;&lt;SPAN&gt;I am looking for dormant detection.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Aug 2022 16:40:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-not-detecting-malicious-files/m-p/511805#M2544</guid>
      <dc:creator>Anil_Racharla</dc:creator>
      <dc:date>2022-08-13T16:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR not detecting malicious files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-not-detecting-malicious-files/m-p/512080#M2559</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/195524"&gt;@Anil_Racharla&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cortex XDR though does dormant file detection, but it is designed to be an execution based detection and prevention solution. Often malwares or malicious files are zipped and compressed with different folders or other files(like jpg files, zip files, etc.). Changing the form factor and entity of the file also changes the property and the hashing of the file. The actual zipped/modified file may not be malicious, but upon execution it opens up a new child executable which might be a malware altogether. The resulting causality chain is malicious and should be the one to be detected and prevented accordingly.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do check for file properties and criteria. Also, you might want to check the policy configuration of the endpoint agent you are testing the samples on.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 07:36:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-not-detecting-malicious-files/m-p/512080#M2559</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2022-08-17T07:36:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR not detecting malicious files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-not-detecting-malicious-files/m-p/513742#M2751</link>
      <description>&lt;P&gt;Also&amp;nbsp; look at the Exploit Profiles as when the virus tries to use a process to start the attack the XDR to monitor that process with an exloit profile so that you are protected from attacks that use not infected file but an application vunrability like buffer overflow etc. and the Restrictions Profiles are nice to limit the attack surface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-profiles" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-profiles&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also run configure automatic &lt;SPAN&gt;&lt;EM&gt;periodic scans&lt;/EM&gt; for what you want&lt;/SPAN&gt;:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-endpoints/scan-endpoint-for-malware" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-endpoints/scan-endpoint-for-malware&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 15:05:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-not-detecting-malicious-files/m-p/513742#M2751</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-09-01T15:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR not detecting malicious files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-not-detecting-malicious-files/m-p/517878#M3020</link>
      <description>&lt;P&gt;If you managed to get the needed answers, please flag the question as answered.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 21:25:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-not-detecting-malicious-files/m-p/517878#M3020</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-10-13T21:25:26Z</dc:date>
    </item>
  </channel>
</rss>

