<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hunting for silver C2 / is cortex blocking it? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hunting-for-sliver-c2-is-cortex-blocking-it/m-p/513846#M2758</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi Rob,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you for submitting a coverage request for the Silver C2.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As for your first question regarding an XQL query, one has not yet been developed by our engineering team at this time.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As for the second question, we are unable to confirm coverage for this type of attack with Cortex XDR. If you would like to receive direct notifications when advances in this coverage may have been deployed, we highly recommend contacting our TAC team at &lt;/SPAN&gt;&lt;A href="https://support.paloaltonetworks.com/" target="_blank"&gt;&lt;SPAN&gt;https://support.paloaltonetworks.com/&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;. They may also be able to provide an XQL query if there is a detection available.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additionally, I was able to contact internal resources regarding this attack as well and can provide coverage/XQL query updates in the LiveCommunity when it is available, however, there is no guarantee that one will be delivered at this time.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Sep 2022 16:03:51 GMT</pubDate>
    <dc:creator>mfakhouri</dc:creator>
    <dc:date>2022-09-02T16:03:51Z</dc:date>
    <item>
      <title>Hunting for sliver C2 / is cortex blocking it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hunting-for-sliver-c2-is-cortex-blocking-it/m-p/512899#M2690</link>
      <description>&lt;P&gt;Hello dear community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone of you some XQL for hunting sliver C2?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/security/blog/2022/08/24/looking-for-the-sliver-lining-hunting-for-emerging-command-and-control-frameworks/" target="_blank" rel="noopener"&gt;https://www.microsoft.com/security/blog/2022/08/24/looking-for-the-sliver-lining-hunting-for-emerging-command-and-control-frameworks/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is Cortex XDR (pro) preventing us?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Sep 2022 09:44:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hunting-for-sliver-c2-is-cortex-blocking-it/m-p/512899#M2690</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-09-03T09:44:13Z</dc:date>
    </item>
    <item>
      <title>Re: Hunting for silver C2 / is cortex blocking it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hunting-for-sliver-c2-is-cortex-blocking-it/m-p/513846#M2758</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Rob,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you for submitting a coverage request for the Silver C2.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As for your first question regarding an XQL query, one has not yet been developed by our engineering team at this time.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As for the second question, we are unable to confirm coverage for this type of attack with Cortex XDR. If you would like to receive direct notifications when advances in this coverage may have been deployed, we highly recommend contacting our TAC team at &lt;/SPAN&gt;&lt;A href="https://support.paloaltonetworks.com/" target="_blank"&gt;&lt;SPAN&gt;https://support.paloaltonetworks.com/&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;. They may also be able to provide an XQL query if there is a detection available.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additionally, I was able to contact internal resources regarding this attack as well and can provide coverage/XQL query updates in the LiveCommunity when it is available, however, there is no guarantee that one will be delivered at this time.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2022 16:03:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hunting-for-sliver-c2-is-cortex-blocking-it/m-p/513846#M2758</guid>
      <dc:creator>mfakhouri</dc:creator>
      <dc:date>2022-09-02T16:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: Hunting for sliver C2 / is cortex blocking it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hunting-for-sliver-c2-is-cortex-blocking-it/m-p/514155#M2766</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Rob,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I was able to confirm that our agent research team is currently adding coverage for the Silver C2 framework. This will utilize static protection with anti-malware flow along with behavioral protection in BTP. If there are additional advances internally, I will be able to continue providing updates in LiveCommunity.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 13:58:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hunting-for-sliver-c2-is-cortex-blocking-it/m-p/514155#M2766</guid>
      <dc:creator>mfakhouri</dc:creator>
      <dc:date>2022-09-07T13:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: Hunting for sliver C2 / is cortex blocking it?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hunting-for-sliver-c2-is-cortex-blocking-it/m-p/514192#M2767</link>
      <description>&lt;P&gt;Hey Mfakhouri,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks a lot!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 20:32:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hunting-for-sliver-c2-is-cortex-blocking-it/m-p/514192#M2767</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-09-07T20:32:03Z</dc:date>
    </item>
  </channel>
</rss>

