<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Prevent Did Not Detect ncat in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-did-not-detect-ncat/m-p/349518#M315</link>
    <description>&lt;P&gt;I run windows defender along with cortex xdr. I have tamper protection on cortex xdr.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Sep 2020 21:29:38 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2020-09-15T21:29:38Z</dc:date>
    <item>
      <title>Cortex XDR Prevent Did Not Detect ncat</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-did-not-detect-ncat/m-p/345089#M259</link>
      <description>&lt;P&gt;Hello I am new to Cortex XDR. I tried ncat on a PC with Cortex XDR Prevent (with Windows Defender) and it did not detect or stop the connection from Kali a PC. Windows Defender showed a warning and once I allowed it I was able to connect on ncat from Kali. Is Cortex XDR Prevent supposed to stop ncat or at least give me an email alert about the connection? Anybody else tried this and with the same result? I will try this with Symantec and will see if Symantec stops the ncat connection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Aug 2020 02:35:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-did-not-detect-ncat/m-p/345089#M259</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-08-23T02:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Prevent Did Not Detect ncat</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-did-not-detect-ncat/m-p/348841#M291</link>
      <description>&lt;P&gt;Consider two things:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Windows Defender should be disabled on PC that runs Cortex XDR. If this does not occur automatically, disable it manually as it could intervene with Cortex XDR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. In case Cortex XDR does not indeed prevent it by default, you can always create a BIOC rule to detect NCAT and then set it as prevention rule inside the Restrictions Profile -&amp;gt; Custom Prevention Rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best,&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Sun, 13 Sep 2020 18:27:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-did-not-detect-ncat/m-p/348841#M291</guid>
      <dc:creator>DKasabji</dc:creator>
      <dc:date>2020-09-13T18:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Prevent Did Not Detect ncat</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-did-not-detect-ncat/m-p/349379#M304</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155222"&gt;@DKasabji&lt;/a&gt;, I am seeing &lt;STRONG&gt;some&lt;/STRONG&gt; devices where Windows Defender Antivirus still have the service running.&amp;nbsp; I disable it via GPO and surprised to see it running on my system.&amp;nbsp; With the new tamper protections I have yet to figure out how to disable the service so it is like it is "off" but still running the app behind the scenes.&amp;nbsp; We are not Intune subscribers so there does not appear to be a way to turn it off if Cortex fails to do so.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 14:37:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-did-not-detect-ncat/m-p/349379#M304</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-09-15T14:37:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Prevent Did Not Detect ncat</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-did-not-detect-ncat/m-p/349380#M305</link>
      <description>&lt;P&gt;@Retired Member, doesn't ncat have legtimate uses so in and of itself it is not evil?&amp;nbsp; Do you have the grayware protection enabled? (Just thinking out loud...I am not experienced with Kali or ncat.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 14:42:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-did-not-detect-ncat/m-p/349380#M305</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-09-15T14:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Prevent Did Not Detect ncat</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-did-not-detect-ncat/m-p/349512#M312</link>
      <description>&lt;P&gt;@Retired Member&amp;nbsp;Aren't you able to disable Tamper protection on Windows? That way you can disable Defender via GPO.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 21:12:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-did-not-detect-ncat/m-p/349512#M312</guid>
      <dc:creator>DKasabji</dc:creator>
      <dc:date>2020-09-15T21:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Prevent Did Not Detect ncat</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-did-not-detect-ncat/m-p/349517#M314</link>
      <description>&lt;P&gt;ncat is a legitmate software but it can be used maliciouisly by bad guys. Kali is a network penetration software that is used by white and black hat hackers. I ran ncat on my windows machine and I connected with ncat from my Kali machine. I used ncat&amp;nbsp; (without e) by nmap because the actual netcat (with e) is blocked by windows defender and cortex. We upgraded to Cortex XDR pro and I should be able to create BIOC rules to give me alert when ncat is used in my network.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 21:28:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-did-not-detect-ncat/m-p/349517#M314</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-09-15T21:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Prevent Did Not Detect ncat</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-did-not-detect-ncat/m-p/349518#M315</link>
      <description>&lt;P&gt;I run windows defender along with cortex xdr. I have tamper protection on cortex xdr.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 21:29:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-did-not-detect-ncat/m-p/349518#M315</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-09-15T21:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Prevent Did Not Detect ncat</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-did-not-detect-ncat/m-p/349545#M316</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155222"&gt;@DKasabji&lt;/a&gt;, No it cannot be disabled any longer unless you have an Intune subscription per MS documentation (link below).&amp;nbsp; Our GPO has had Windows Defender turned off for many years now going back to before we added Cortex XDR Prevent to our environment.&amp;nbsp; (The prior solution did not disable automatically so we have always used the GPO setting.)&amp;nbsp; The GPO setting is active and Defender has never been observed doing anything on our systems to my knowledge.&amp;nbsp; But for some reason some systems, all running Win10 v1903, some systems have the Windows Defender Antivirus Service running and others do not.&amp;nbsp; I am going to guess that this was an issue before Cortex XDR Prevent and it was just not noticed.&amp;nbsp; We have an application misbehaving and the vendor claims Windows Defender is the cause so as part of my info gathering I noticed the service running on the system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/prevent-changes-to-security-settings-with-tamper-protection" target="_blank"&gt;https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/prevent-changes-to-security-settings-with-tamper-protection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 22:09:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-did-not-detect-ncat/m-p/349545#M316</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-09-15T22:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Prevent Did Not Detect ncat</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-did-not-detect-ncat/m-p/355589#M351</link>
      <description>&lt;P&gt;I created IOC using ncat.exe and I get an alert from XDR when I tried to use ncat. I will decide later if I should to ahead and block it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also created IOC tor nmap.exe and tor.exe.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Oct 2020 01:08:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-prevent-did-not-detect-ncat/m-p/355589#M351</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-10-11T01:08:59Z</dc:date>
    </item>
  </channel>
</rss>

