<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Wildfire Test File in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-test-file/m-p/531592#M3657</link>
    <description>&lt;P&gt;Has anyone had issues with the Wildfire Test file not showing up as an alert in the cloud? On the workstation it's getting blocked just fine. I haven't had a regular alert fire in about 2 months. Just wondering if I have an underlying communication issue. Also looked at the logs to verified no proxies are setup.&lt;/P&gt;</description>
    <pubDate>Fri, 17 Feb 2023 15:43:55 GMT</pubDate>
    <dc:creator>Chris_Dietz</dc:creator>
    <dc:date>2023-02-17T15:43:55Z</dc:date>
    <item>
      <title>Wildfire Test File</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-test-file/m-p/531592#M3657</link>
      <description>&lt;P&gt;Has anyone had issues with the Wildfire Test file not showing up as an alert in the cloud? On the workstation it's getting blocked just fine. I haven't had a regular alert fire in about 2 months. Just wondering if I have an underlying communication issue. Also looked at the logs to verified no proxies are setup.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 15:43:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-test-file/m-p/531592#M3657</guid>
      <dc:creator>Chris_Dietz</dc:creator>
      <dc:date>2023-02-17T15:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Test File</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-test-file/m-p/531659#M3658</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/170485"&gt;@Chris_Dietz&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Thank you for writing to Live Community.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;What you’re describing could stem from a variety of reasons.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;1. You mention you have not seen an alert in months, are you using the same test pe file on both machines? Have you tried downloading a&amp;nbsp; new &lt;/SPAN&gt;&lt;A href="https://wildfire.paloaltonetworks.com/publicapi/test/pe" target="_blank"&gt;&lt;SPAN&gt;test pe file&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; and checking if it generates alerts in your cloud environment?&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;2. If downloading a new file does not trigger the alerts again, please take a look at the &lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Alert-Exclusions" target="_blank"&gt;&lt;SPAN&gt;alert exclusions&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; configurations by going into Settings → Exception Configuration → Alert Exclusions&amp;nbsp; a&lt;/SPAN&gt;&lt;SPAN&gt;nd check if there’s an existing rule to suppress this type of alerts.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;3. If you did not find it under alert exclusion, please go into&lt;/SPAN&gt; &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Add-an-IOC-or-BIOC-Rule-Exception" target="_blank"&gt;&lt;SPAN&gt;IOC/BIOC&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; suppression settings by going into Settings → Exception Configuration → IOC/BIOC Suppression Rules and make sure there is no suppression rule set to prevent the test pe file from running.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;4. You raised concerns about the file not getting blocked. Can you log into your VM and try a &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Scan-an-Endpoint-for-Malware" target="_self"&gt;custom scan&lt;/A&gt;? You can initiate a scan on demand to examine a specific file or folder. If there aren’t any settings allowing this specific file to run (hash-allow list or exception) it should be blocked.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Please let me know if any of these steps helped!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Feb 2023 17:07:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-test-file/m-p/531659#M3658</guid>
      <dc:creator>mavraham</dc:creator>
      <dc:date>2023-02-19T17:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Test File</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-test-file/m-p/531742#M3662</link>
      <description>&lt;P&gt;Hi, yes I tried the same test pe file on both machines. I downloaded a fresh copy to see if anything changed, and it had not. Verified no exceptions this morning in both places you recommended. Currently running a malware scan now to see if it will pick it up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The strange thing is that it will block it on the local machine, however I'm not getting a cloud alert for it. I noticed that there was a hot fix CPATR-18853 that might have something to do with it. Any ideas on what to do from here?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 12:39:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-test-file/m-p/531742#M3662</guid>
      <dc:creator>Chris_Dietz</dc:creator>
      <dc:date>2023-02-20T12:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Test File</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-test-file/m-p/531744#M3663</link>
      <description>&lt;P&gt;Also ran a custom scan on the file itself. It identifies correctly as a suspicious file, however the alert is not getting to the cloud and I'm not getting an email notification. Thanks for the steps. I'm going to make some notes and initiate a support ticket.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 12:55:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-test-file/m-p/531744#M3663</guid>
      <dc:creator>Chris_Dietz</dc:creator>
      <dc:date>2023-02-20T12:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Test File</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-test-file/m-p/531775#M3666</link>
      <description>&lt;P&gt;Thanks for sharing&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/170485"&gt;@Chris_Dietz&lt;/a&gt;.&lt;BR /&gt;&lt;BR /&gt;In this instance, a support ticket would indeed be more useful, as you'd be able to share with us screenshots and configurations you wouldn't want to exposed in a public forum.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Just a quick note - email notification exclusions are different than alert exclusions. However, if you're not seeing the alert at all then a support ticket is still warranted.&lt;BR /&gt;&lt;BR /&gt;Hope you are able to solve this quickly.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 17:47:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-test-file/m-p/531775#M3666</guid>
      <dc:creator>mavraham</dc:creator>
      <dc:date>2023-02-20T17:47:04Z</dc:date>
    </item>
  </channel>
</rss>

