<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic OriginalFileName from VERSIONINFO in Cortex XDR Pro in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/originalfilename-from-versioninfo-in-cortex-xdr-pro/m-p/537340#M4014</link>
    <description>&lt;P&gt;Hey dear community,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Threat actors often rename apps. Like a.exe instead of anydesk.exe. But they do not change the versioninfo.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=oMAvSpq9fYY" target="_blank"&gt;https://www.youtube.com/watch?v=oMAvSpq9fYY&lt;/A&gt;&amp;nbsp;--&amp;gt; Minute 37&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to track this with cortex xdr pro?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
    <pubDate>Sun, 02 Apr 2023 00:02:39 GMT</pubDate>
    <dc:creator>RFeyertag</dc:creator>
    <dc:date>2023-04-02T00:02:39Z</dc:date>
    <item>
      <title>OriginalFileName from VERSIONINFO in Cortex XDR Pro</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/originalfilename-from-versioninfo-in-cortex-xdr-pro/m-p/537340#M4014</link>
      <description>&lt;P&gt;Hey dear community,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Threat actors often rename apps. Like a.exe instead of anydesk.exe. But they do not change the versioninfo.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=oMAvSpq9fYY" target="_blank"&gt;https://www.youtube.com/watch?v=oMAvSpq9fYY&lt;/A&gt;&amp;nbsp;--&amp;gt; Minute 37&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to track this with cortex xdr pro?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Sun, 02 Apr 2023 00:02:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/originalfilename-from-versioninfo-in-cortex-xdr-pro/m-p/537340#M4014</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-04-02T00:02:39Z</dc:date>
    </item>
    <item>
      <title>Re: OriginalFileName from VERSIONINFO in Cortex XDR Pro</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/originalfilename-from-versioninfo-in-cortex-xdr-pro/m-p/537343#M4015</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think you can use something like below to track/hunt for the use case in question:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;config case_sensitive = false 
| dataset = xdr_data 
| filter event_type = ENUM.LOAD_IMAGE and event_sub_type = ENUM.LOAD_IMAGE_MODULE 
| alter File_Version = json_extract_scalar(action_module_file_info,"$.file_version")
| alter Product_Version = json_extract_scalar(action_module_file_info,"$.product_version")
| alter Company = json_extract_scalar(action_module_file_info,"$.company")
| alter Description = json_extract_scalar(action_module_file_info,"$.description")
| alter internal_name = json_extract_scalar(action_module_file_info,"$.internal_name")
| alter original_name = json_extract_scalar(action_module_file_info,"$.original_name")
| alter only_exe = arrayindex(regextract(action_module_path,"^.+\\(.*?)$"),0)
| filter only_exe contains ".exe"
| fields only_exe as Filename, internal_name, original_name, File_Version, Company, Product_Version, Description, actor_process_image_name as Process, action_module_path as Path
| limit 500&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have seen XDR in live where renaming instance of cmd.exe to something else and executing commands alerts in XDR.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Apr 2023 04:29:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/originalfilename-from-versioninfo-in-cortex-xdr-pro/m-p/537343#M4015</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2023-04-02T04:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: OriginalFileName from VERSIONINFO in Cortex XDR Pro</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/originalfilename-from-versioninfo-in-cortex-xdr-pro/m-p/538024#M4063</link>
      <description>&lt;P&gt;Thank you very much!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 23:00:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/originalfilename-from-versioninfo-in-cortex-xdr-pro/m-p/538024#M4063</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-04-07T23:00:16Z</dc:date>
    </item>
  </channel>
</rss>

