<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512165#M2589</link>
    <description>&lt;P&gt;Do we know for sure that even if the referenced windows update in those articles (below) gets installed, that the Cortex BTP no longer affects the system?&amp;nbsp; If it still does affect things, then we need a better answer than to whitelist a critical component of Windows that plenty of malware targets.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Isn't there a way to do a BTP exception within BTP somehow vs global exception of svchost.exe?&lt;/P&gt;
&lt;H1 id="page-header" class=""&gt;KB5012170&amp;nbsp;&lt;/H1&gt;</description>
    <pubDate>Wed, 17 Aug 2022 17:07:12 GMT</pubDate>
    <dc:creator>derekmayberry</dc:creator>
    <dc:date>2022-08-17T17:07:12Z</dc:date>
    <item>
      <title>Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512084#M2561</link>
      <description>&lt;P&gt;We are observing VEEAM VeeamTransportSvc.exe being blocked by BTP and, thus, preventing backups from being started.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;We are working on a temporary fix excluding path and cgo and the likes but this is the second week in a row that content updates are screwing, this time impacting operations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Already filled a support case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 07:44:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512084#M2561</guid>
      <dc:creator>RobertoPastorino</dc:creator>
      <dc:date>2022-08-17T07:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512087#M2563</link>
      <description>&lt;P&gt;Our observed CGO&lt;/P&gt;
&lt;P&gt;C:\Windows\system32\svchost.exe -k netsvcs -p -s Winmgmt&lt;BR /&gt;C:\Windows\system32\svchost.exe -k netsvcs&lt;BR /&gt;C:\\Program&amp;nbsp;Files&amp;nbsp;(x86)\\Veeam\\Backup&amp;nbsp;Transport\\VeeamTransportSvc.exe\""&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All trying to modify a specific reg key:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;key_name":&amp;nbsp;"bcd00000000\\objects\\{d80ed0e8-d6da-11e7-b27f-ab3a45175c5d}\\elements\\25000080"&lt;/P&gt;
&lt;P&gt;"value":&amp;nbsp;"base64:&amp;nbsp;AgAAAAAAAAA="&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;AgAAAAAAAA= it's a NULL sledge , effectively impeding the boot in safe mode.&lt;BR /&gt;(valid values are: &lt;SPAN&gt;0 =&amp;nbsp;&lt;SPAN class="" title="keyword"&gt;Minimal &lt;SPAN&gt;1 =&amp;nbsp;&lt;SPAN class="" title="keyword"&gt;Network &lt;SPAN&gt;2 =&amp;nbsp;&lt;SPAN class="" title="keyword"&gt;DsRepair)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 09:14:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512087#M2563</guid>
      <dc:creator>RobertoPastorino</dc:creator>
      <dc:date>2022-08-17T09:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512097#M2566</link>
      <description>&lt;P&gt;We need to get this solved, it's blocking the jobs that use application aware. Identical error to yours, i'm just not sure how to make an exception to stop veeam from blocking it. first time i've had to make an exception in cortex xdr.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 11:35:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512097#M2566</guid>
      <dc:creator>DavidStevens</dc:creator>
      <dc:date>2022-08-17T11:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512099#M2567</link>
      <description>&lt;P&gt;We are also seeing this problem all domain controllers this morning. I may whitelist and wait for a response from PA on whether a new content update will allow me to undo a whitelist entry.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 12:11:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512099#M2567</guid>
      <dc:creator>parkerjr2</dc:creator>
      <dc:date>2022-08-17T12:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512105#M2569</link>
      <description>&lt;P&gt;Our Veeam backups on our DCs are also broken as of this morning.&amp;nbsp; The only way I see to whitelist this is by adding the hash for SVCHOST.exe... seems too risky at this point in time.&amp;nbsp; I'll create a support ticket as well, but please do post your responses from support.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 12:56:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512105#M2569</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2022-08-17T12:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512111#M2570</link>
      <description>&lt;P&gt;Same issue for me this morning.&amp;nbsp; Had weird errors I'd never seen in the Veeam backup reports and I am glad to see this thread.&amp;nbsp; Hopefully a new BTP update will release today to resolve.&amp;nbsp; We obviously can't whitlelist svchost.exe.&amp;nbsp; I opened a ticket just now and will reply with the response.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 13:51:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512111#M2570</guid>
      <dc:creator>derekmayberry</dc:creator>
      <dc:date>2022-08-17T13:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512112#M2571</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have received a number of TAC cases regarding this issue and our engineering team is aware and working to address.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 13:53:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512112#M2571</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2022-08-17T13:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512114#M2572</link>
      <description>&lt;P&gt;It does only appear to be affecting application aware backups&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 14:10:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512114#M2572</guid>
      <dc:creator>ianatgrafton</dc:creator>
      <dc:date>2022-08-17T14:10:00Z</dc:date>
    </item>
    <item>
      <title>Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512120#M2573</link>
      <description>&lt;P&gt;We have a support case currently opened with Palo for this issue and their suggestion was to whitelist this activity, but we have done that and just tried to kick off backups of our Domain Controllers and it is failing now. Seems that the registry and BCD editing that XDR blocked that VEEAM was trying to make yesterday evening, isn't something that VEEAM writes again (or just assumes that the changes took when XDR prevented them from happening) upon re-try of the backup jobs?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 14:40:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512120#M2573</guid>
      <dc:creator>Brad_Lape</dc:creator>
      <dc:date>2022-08-17T14:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512128#M2574</link>
      <description>&lt;P&gt;I saw the same behavior this morning. I didn't realize at the time that Cortex was catching it, so I was troubleshooting otherwise. I ended up re-registering VSS components twice and that seemed to resolve my issues.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 15:06:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512128#M2574</guid>
      <dc:creator>jturner_storm7</dc:creator>
      <dc:date>2022-08-17T15:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512135#M2576</link>
      <description>&lt;P&gt;we have the same problem... i waiting for response for support pls!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 15:26:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512135#M2576</guid>
      <dc:creator>ebourdajorge</dc:creator>
      <dc:date>2022-08-17T15:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512140#M2578</link>
      <description>&lt;P&gt;Are the VSS components you are talking about, this:&amp;nbsp;&lt;A href="https://www.veeam.com/kb2041" target="_blank"&gt;https://www.veeam.com/kb2041&lt;/A&gt;&amp;nbsp;?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 15:38:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512140#M2578</guid>
      <dc:creator>Brad_Lape</dc:creator>
      <dc:date>2022-08-17T15:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512141#M2579</link>
      <description>&lt;P&gt;Here's one script that I ran:&lt;BR /&gt;net stop "System Event Notification Service" /y&lt;BR /&gt;net stop "Background Intelligent Transfer Service" /y&lt;BR /&gt;net stop "COM+ Event System" /y&lt;BR /&gt;net stop "Microsoft Software Shadow Copy Provider" /y&lt;BR /&gt;net stop "Volume Shadow Copy" /y&lt;BR /&gt;cd /d %windir%\system32&lt;BR /&gt;net stop vss&lt;BR /&gt;net stop swprv&lt;BR /&gt;regsvr32 /s ATL.DLL&lt;BR /&gt;regsvr32 /s comsvcs.DLL&lt;BR /&gt;regsvr32 /s credui.DLL&lt;BR /&gt;regsvr32 /s CRYPTNET.DLL&lt;BR /&gt;regsvr32 /s CRYPTUI.DLL&lt;BR /&gt;regsvr32 /s dhcpqec.DLL&lt;BR /&gt;regsvr32 /s dssenh.DLL&lt;BR /&gt;regsvr32 /s eapqec.DLL&lt;BR /&gt;regsvr32 /s esscli.DLL&lt;BR /&gt;regsvr32 /s FastProx.DLL&lt;BR /&gt;regsvr32 /s FirewallAPI.DLL&lt;BR /&gt;regsvr32 /s kmsvc.DLL&lt;BR /&gt;regsvr32 /s lsmproxy.DLL&lt;BR /&gt;regsvr32 /s MSCTF.DLL&lt;BR /&gt;regsvr32 /s msi.DLL&lt;BR /&gt;regsvr32 /s msxml3.DLL&lt;BR /&gt;regsvr32 /s ncprov.DLL&lt;BR /&gt;regsvr32 /s ole32.DLL&lt;BR /&gt;regsvr32 /s OLEACC.DLL&lt;BR /&gt;regsvr32 /s OLEAUT32.DLL&lt;BR /&gt;regsvr32 /s PROPSYS.DLL&lt;BR /&gt;regsvr32 /s QAgent.DLL&lt;BR /&gt;regsvr32 /s qagentrt.DLL&lt;BR /&gt;regsvr32 /s QUtil.DLL&lt;BR /&gt;regsvr32 /s raschap.DLL&lt;BR /&gt;regsvr32 /s RASQEC.DLL&lt;BR /&gt;regsvr32 /s rastls.DLL&lt;BR /&gt;regsvr32 /s repdrvfs.DLL&lt;BR /&gt;regsvr32 /s RPCRT4.DLL&lt;BR /&gt;regsvr32 /s rsaenh.DLL&lt;BR /&gt;regsvr32 /s SHELL32.DLL&lt;BR /&gt;regsvr32 /s shsvcs.DLL&lt;BR /&gt;regsvr32 /s /i swprv.DLL&lt;BR /&gt;regsvr32 /s tschannel.DLL&lt;BR /&gt;regsvr32 /s USERENV.DLL&lt;BR /&gt;regsvr32 /s vss_ps.DLL&lt;BR /&gt;regsvr32 /s wbemcons.DLL&lt;BR /&gt;regsvr32 /s wbemcore.DLL&lt;BR /&gt;regsvr32 /s wbemess.DLL&lt;BR /&gt;regsvr32 /s wbemsvc.DLL&lt;BR /&gt;regsvr32 /s WINHTTP.DLL&lt;BR /&gt;regsvr32 /s WINTRUST.DLL&lt;BR /&gt;regsvr32 /s wmiprvsd.DLL&lt;BR /&gt;regsvr32 /s wmisvc.DLL&lt;BR /&gt;regsvr32 /s wmiutils.DLL&lt;BR /&gt;regsvr32 /s wuaueng.DLL&lt;BR /&gt;sfc /SCANFILE=%windir%\system32\catsrv.DLL&lt;BR /&gt;sfc /SCANFILE=%windir%\system32\catsrvut.DLL&lt;BR /&gt;sfc /SCANFILE=%windir%\system32\CLBCatQ.DLL&lt;BR /&gt;net start "COM+ Event System"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And here is the other:&lt;/P&gt;
&lt;P&gt;cd /d %windir%\system32&lt;BR /&gt;net stop vss&lt;BR /&gt;net stop swprv&lt;BR /&gt;regsvr32 /s ole32.dll&lt;BR /&gt;regsvr32 /s oleaut32.dll&lt;BR /&gt;regsvr32 /s vss_ps.dll&lt;BR /&gt;vssvc /register&lt;BR /&gt;regsvr32 /s /i swprv.dll&lt;BR /&gt;regsvr32 /s /i eventcls.dll&lt;BR /&gt;regsvr32 /s es.dll&lt;BR /&gt;regsvr32 /s stdprov.dll&lt;BR /&gt;regsvr32 /s vssui.dll&lt;BR /&gt;regsvr32 /s msxml.dll&lt;BR /&gt;regsvr32 /s msxml3.dll&lt;BR /&gt;regsvr32 /s msxml4.dll&lt;BR /&gt;vssvc /register&lt;BR /&gt;net start swprv&lt;BR /&gt;net start vss&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Validate that all necessary services on your DC are running when finished. I had to restart my DHCP server service, which was stopped in the process.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 15:43:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512141#M2579</guid>
      <dc:creator>jturner_storm7</dc:creator>
      <dc:date>2022-08-17T15:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512143#M2580</link>
      <description>&lt;P&gt;Thank you, J Turner, do all those commands fix this issue then:&amp;nbsp;&lt;A href="https://www.veeam.com/kb1697" target="_blank"&gt;https://www.veeam.com/kb1697&lt;/A&gt;&amp;nbsp;?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 15:50:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512143#M2580</guid>
      <dc:creator>Brad_Lape</dc:creator>
      <dc:date>2022-08-17T15:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512144#M2581</link>
      <description>&lt;P&gt;I can tell you that it fixed my issues, which were identical to what was in the original post. I had 5 events in cortex appear for each server, and veeam jobs were failing until I went through and ran these. Also to note I did update my servers with latest patches as well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 15:58:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512144#M2581</guid>
      <dc:creator>jturner_storm7</dc:creator>
      <dc:date>2022-08-17T15:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512151#M2582</link>
      <description>&lt;P&gt;My DC backups usually take less than 2 minutes each so I have contemplated trying to disable the tool for that time and run the backup.&lt;BR /&gt;&lt;BR /&gt;"c:\program files\palo alto networks\traps\cytool.exe" protect disable&lt;/P&gt;
&lt;P&gt;then after the backup&lt;BR /&gt;"c:\program files\palo alto networks\traps\cytool.exe" protect enable&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 16:13:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512151#M2582</guid>
      <dc:creator>parkerjr2</dc:creator>
      <dc:date>2022-08-17T16:13:48Z</dc:date>
    </item>
    <item>
      <title>Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512152#M2583</link>
      <description>&lt;P&gt;That should work according to what I've read as a stop gap until cortex tram figures out what caused the false trigger.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 16:15:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512152#M2583</guid>
      <dc:creator>jturner_storm7</dc:creator>
      <dc:date>2022-08-17T16:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512153#M2584</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The best way to prevent this behavior from being blocked in my opinion is to create an alert exception:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Right click the alert&lt;/LI&gt;
&lt;LI&gt;Click "Manage Alert"&lt;/LI&gt;
&lt;LI&gt;Click "Create Alert Exception"&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CSGandD_1-1660752639087.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43199i2257229D97819E87/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CSGandD_1-1660752639087.png" alt="CSGandD_1-1660752639087.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;LI&gt;Check the options "CGO Process Path" and then "CGO Command Arguments"&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CSGandD_2-1660752772341.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43200i63B2A20E474DF406/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CSGandD_2-1660752772341.png" alt="CSGandD_2-1660752772341.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;Select the desired scope and then click "Create"&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Please note that this Behavioral Threat is an attempt by Palo Alto to detect the exploitation of recently released boot vulnerabilities:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.bleepingcomputer.com/news/security/microsoft-blocks-uefi-bootloaders-enabling-windows-secure-boot-bypass/" target="_blank" rel="noopener"&gt;https://www.bleepingcomputer.com/news/security/microsoft-blocks-uefi-bootloaders-enabling-windows-secure-boot-bypass/&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.bleepingcomputer.com/news/security/microsoft-blocks-uefi-bootloaders-enabling-windows-secure-boot-bypass/#:~:text=In%20an%20advisory,vendor%2C%20if%20available." target="_self"&gt;Check if your bootloaders are vulnerable to this!&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Edit: This detection may more specifically relate to detecting boot configuration changes used by ransomware groups, that said, I can imagine both techniques being used in tandem:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.binarydefense.com/detecting-ransomwares-stealthy-boot-configuration-edits/" target="_blank"&gt;https://www.binarydefense.com/detecting-ransomwares-stealthy-boot-configuration-edits/&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 16:45:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512153#M2584</guid>
      <dc:creator>CSGandD</dc:creator>
      <dc:date>2022-08-17T16:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512154#M2585</link>
      <description>&lt;P&gt;The only downside to this is that there would now be an exception and it could be exploited by a legit threat.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 16:21:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512154#M2585</guid>
      <dc:creator>jturner_storm7</dc:creator>
      <dc:date>2022-08-17T16:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: Another week, another BTP quirk: Behavioral threat detected (rule: sync.enable_safemode_on_next_reboot) spawned from VEEAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512157#M2586</link>
      <description>&lt;P&gt;You are absolutely correct. Ideally, if the block is not impacting, it shouldn't be removed.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;If it is impacting, the vulnerabilities should be mitigated prior to removing the block if possible&lt;/LI&gt;
&lt;LI&gt;If they cannot be mitigated without removing the block:
&lt;UL&gt;
&lt;LI&gt;Disconnect the host from the network&lt;/LI&gt;
&lt;LI&gt;Remove the block&lt;/LI&gt;
&lt;LI&gt;Apply the available patch&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;And finally, if the block needs to be removed AND host cannot be disconnected from the network due to essential services being impacted:
&lt;UL&gt;
&lt;LI&gt;Cross your fingers, close your eyes, remove the block and then apply the patch if this is within your risk tolerances, lol&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Best of luck to all, hopefully more targeted indicators of the actual exploits are identified soon!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 16:30:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/another-week-another-btp-quirk-behavioral-threat-detected-rule/m-p/512157#M2586</guid>
      <dc:creator>CSGandD</dc:creator>
      <dc:date>2022-08-17T16:30:28Z</dc:date>
    </item>
  </channel>
</rss>

