<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: rare iptable delete command in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/rare-iptable-delete-command/m-p/525470#M3307</link>
    <description>&lt;P&gt;Hi Muthuvel,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think the question is how can we see delete/flush command ?&lt;/P&gt;
&lt;P&gt;But event its, still some of the important informations are missing like&lt;/P&gt;
&lt;P&gt;What is the alert source?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you try to&amp;nbsp;investigate casualty chain?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you check&amp;nbsp;action_remote_process_image_command_line or&amp;nbsp;actor_process_command_line fields for parameters?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is your time line correct when you use Query builder?&lt;/P&gt;</description>
    <pubDate>Thu, 29 Dec 2022 14:07:33 GMT</pubDate>
    <dc:creator>etugriceri</dc:creator>
    <dc:date>2022-12-29T14:07:33Z</dc:date>
    <item>
      <title>rare iptable delete command</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/rare-iptable-delete-command/m-p/525348#M3305</link>
      <description>&lt;P&gt;We received couple of alerts on rare iptable delete command.On checking the host activity, we could able to observe all commands including newly entered command in the host machine but not able to see the iptable delete/flush command in the activity log under Query builder.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 10:03:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/rare-iptable-delete-command/m-p/525348#M3305</guid>
      <dc:creator>Muthuvel</dc:creator>
      <dc:date>2022-12-28T10:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: rare iptable delete command</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/rare-iptable-delete-command/m-p/525470#M3307</link>
      <description>&lt;P&gt;Hi Muthuvel,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think the question is how can we see delete/flush command ?&lt;/P&gt;
&lt;P&gt;But event its, still some of the important informations are missing like&lt;/P&gt;
&lt;P&gt;What is the alert source?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you try to&amp;nbsp;investigate casualty chain?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you check&amp;nbsp;action_remote_process_image_command_line or&amp;nbsp;actor_process_command_line fields for parameters?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is your time line correct when you use Query builder?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 14:07:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/rare-iptable-delete-command/m-p/525470#M3307</guid>
      <dc:creator>etugriceri</dc:creator>
      <dc:date>2022-12-29T14:07:33Z</dc:date>
    </item>
  </channel>
</rss>

