<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Perform Memory Acquisition Using XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/perform-memory-acquisition-using-xdr/m-p/515189#M2843</link>
    <description>&lt;P&gt;Hello Neelrohit,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does this protection afect Tools like in the link too?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://medium.com/@balqurneh/bypass-crowdstrike-falcon-edr-protection-against-process-dump-like-lsass-exe-3c163e1b8a3e" target="_blank"&gt;https://medium.com/@balqurneh/bypass-crowdstrike-falcon-edr-protection-against-process-dump-like-lsass-exe-3c163e1b8a3e&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 17 Sep 2022 10:38:50 GMT</pubDate>
    <dc:creator>Cyber1985</dc:creator>
    <dc:date>2022-09-17T10:38:50Z</dc:date>
    <item>
      <title>Perform Memory Acquisition Using XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/perform-memory-acquisition-using-xdr/m-p/515038#M2824</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to acquire memory using Cortex XDR for digital forensics? We are not looking for process dump but a complete memory dump of the system which we can further use with tool like volatility or something.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Kanwar&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 03:46:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/perform-memory-acquisition-using-xdr/m-p/515038#M2824</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2022-09-16T03:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: Perform Memory Acquisition Using XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/perform-memory-acquisition-using-xdr/m-p/515044#M2826</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163390"&gt;@KanwarSingh01&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to Live Community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;WIth the advent of Cortex XDR 3.4, we support memory collection using forensics add on module. Please navigate to forensics&amp;gt; Triage&amp;gt;Configurations and create a configuration of your choice with memory collection enabled.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-09-16 at 1.18.06 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43897iFFAB63BE88DC9950/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2022-09-16 at 1.18.06 PM.png" alt="Screenshot 2022-09-16 at 1.18.06 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;Please be advised that as of now memory collection is available as an offline collector only and should not be run on endpoints running Cortex XDR agents as the agent code conflict will prevent a memory collection.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a fix to this conflict targetted for XDR agent version 7.9 which also in turns targets to bring agent based memory dump collection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that answers you question!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 05:24:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/perform-memory-acquisition-using-xdr/m-p/515044#M2826</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2022-09-16T05:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: Perform Memory Acquisition Using XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/perform-memory-acquisition-using-xdr/m-p/515182#M2841</link>
      <description>&lt;P&gt;Hey neelrohit,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So as I understand, if we want to use the offline collector for forensics we should deactivate or uninstall the agent until agent Version 7.9?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Sat, 17 Sep 2022 08:56:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/perform-memory-acquisition-using-xdr/m-p/515182#M2841</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-09-17T08:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: Perform Memory Acquisition Using XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/perform-memory-acquisition-using-xdr/m-p/515186#M2842</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206384"&gt;@Cyber1985&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is correct. As of now, if we have to perform memory collection, we might have to disable the agent service or pause endpoint protection for this capability to work seamlessly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Sep 2022 09:15:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/perform-memory-acquisition-using-xdr/m-p/515186#M2842</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2022-09-17T09:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: Perform Memory Acquisition Using XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/perform-memory-acquisition-using-xdr/m-p/515189#M2843</link>
      <description>&lt;P&gt;Hello Neelrohit,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does this protection afect Tools like in the link too?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://medium.com/@balqurneh/bypass-crowdstrike-falcon-edr-protection-against-process-dump-like-lsass-exe-3c163e1b8a3e" target="_blank"&gt;https://medium.com/@balqurneh/bypass-crowdstrike-falcon-edr-protection-against-process-dump-like-lsass-exe-3c163e1b8a3e&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Sep 2022 10:38:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/perform-memory-acquisition-using-xdr/m-p/515189#M2843</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-09-17T10:38:50Z</dc:date>
    </item>
  </channel>
</rss>

