<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;SecureDriveService.dll&amp;quot; in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quot-securedriveservice-dll-quot/m-p/516671#M2941</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/235905"&gt;@jesusyas&lt;/a&gt;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To further assess if the verdict reported is a false positive, details of the WildFire analysis can be reviewed. To open the WildFire Analysis Report:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Navigate to the relevant incident. Right-click the Incident and select “View Incident”&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;From the “Key Artifacts” list incorporated with the Incident, select the report icon&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;as demonstrated. This will take you to the WildFire Analysis Report.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mfakhouri_1-1664820602324.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44358iBCF659FD95DB535F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="mfakhouri_1-1664820602324.png" alt="mfakhouri_1-1664820602324.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This report will contain detailed sample information leading up to the case of the WildFire verdict.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If the verdict is determined to be a false positive, a report&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;can be made at the top right of the WildFire Analysis Report menu. This will report the error to our threat team.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mfakhouri_3-1664820602337.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44362iE6A9C6917C2D040A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="mfakhouri_3-1664820602337.png" alt="mfakhouri_3-1664820602337.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you are still unable to confirm the validity of the detected file, we highly recommend submitting a support ticket to identify and remediate the issue at &lt;/SPAN&gt;&lt;A href="http://support.paloaltonetworks.com" target="_blank"&gt;&lt;SPAN&gt;support.paloaltonetworks.com&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;. This will ensure that the issue is documented and a fix is implemented if there is a false positive.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Reference:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-files/review-wildfire-analysis-details" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-files/review-wildfire-analysis-details&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Oct 2022 18:22:02 GMT</pubDate>
    <dc:creator>mfakhouri</dc:creator>
    <dc:date>2022-10-03T18:22:02Z</dc:date>
    <item>
      <title>"SecureDriveService.dll"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quot-securedriveservice-dll-quot/m-p/516610#M2940</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;While performing a malware analysis on Cortex XDR, Wildfire has detected a file on the computer as possible malware. The file has also been analyzed in other intelligence tools and has not been detected as malicious, the only tool that detects it as malware is Palo Alto Networks. It is the file "SecureDriveService.dll", with description PE32+ executable (DLL) (GUI) x86-64, for MS Windows, with SHA256: e69a1b28a5b71549177f09a9ef7a336831400479ce6f3c6856bc8a818170745d.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please , could you give us some feedback and indicate if it can be treated as false positive?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT&gt;BR&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 10:42:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quot-securedriveservice-dll-quot/m-p/516610#M2940</guid>
      <dc:creator>jesusyas</dc:creator>
      <dc:date>2022-10-03T10:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: "SecureDriveService.dll"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quot-securedriveservice-dll-quot/m-p/516671#M2941</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/235905"&gt;@jesusyas&lt;/a&gt;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To further assess if the verdict reported is a false positive, details of the WildFire analysis can be reviewed. To open the WildFire Analysis Report:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Navigate to the relevant incident. Right-click the Incident and select “View Incident”&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;From the “Key Artifacts” list incorporated with the Incident, select the report icon&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;as demonstrated. This will take you to the WildFire Analysis Report.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mfakhouri_1-1664820602324.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44358iBCF659FD95DB535F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="mfakhouri_1-1664820602324.png" alt="mfakhouri_1-1664820602324.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This report will contain detailed sample information leading up to the case of the WildFire verdict.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If the verdict is determined to be a false positive, a report&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;can be made at the top right of the WildFire Analysis Report menu. This will report the error to our threat team.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mfakhouri_3-1664820602337.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44362iE6A9C6917C2D040A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="mfakhouri_3-1664820602337.png" alt="mfakhouri_3-1664820602337.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you are still unable to confirm the validity of the detected file, we highly recommend submitting a support ticket to identify and remediate the issue at &lt;/SPAN&gt;&lt;A href="http://support.paloaltonetworks.com" target="_blank"&gt;&lt;SPAN&gt;support.paloaltonetworks.com&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;. This will ensure that the issue is documented and a fix is implemented if there is a false positive.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Reference:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-files/review-wildfire-analysis-details" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-files/review-wildfire-analysis-details&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 18:22:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/quot-securedriveservice-dll-quot/m-p/516671#M2941</guid>
      <dc:creator>mfakhouri</dc:creator>
      <dc:date>2022-10-03T18:22:02Z</dc:date>
    </item>
  </channel>
</rss>

