<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: A question from Cortex XDR Active Scanning Webinar: Failed attempt alert in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-cortex-xdr-active-scanning-webinar-failed/m-p/539228#M4183</link>
    <description>&lt;P&gt;A reply by:&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/142551"&gt;@neelrohit&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We have tamper protection as a feature, and if someone tries unauthorized access or attempts to disable the agent using the means which is not supposed to be(eg, disabling registry, taskkill commands etc.) Cortex XDR will generate prevention or detection alerts for the same. However, if you disable the agent using cytool commands, we do not get alerts. These events are, however, logged-in agent audit logs and can be forwarded as notifications or created as correlation rules to generate alerts.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Apr 2023 16:44:23 GMT</pubDate>
    <dc:creator>rtsedaka</dc:creator>
    <dc:date>2023-04-18T16:44:23Z</dc:date>
    <item>
      <title>A question from Cortex XDR Active Scanning Webinar: Failed attempt alert</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-cortex-xdr-active-scanning-webinar-failed/m-p/539227#M4182</link>
      <description>&lt;P&gt;Is there an alert for a failed attempt/attempts to stop the Cortex Service on an Endpoint?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;*Note: This question was asked as part of the&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-webinars/cortex-xdr-customer-success-webinar-active-scanning/ta-p/536976" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Cortex XDR Customer Success Webinar: Active Scanning&lt;/STRONG&gt;&lt;/A&gt;&lt;BR /&gt;We encourage you to review the webinar article for additional resources.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 16:43:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-cortex-xdr-active-scanning-webinar-failed/m-p/539227#M4182</guid>
      <dc:creator>rtsedaka</dc:creator>
      <dc:date>2023-04-18T16:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: A question from Cortex XDR Active Scanning Webinar: Failed attempt alert</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-cortex-xdr-active-scanning-webinar-failed/m-p/539228#M4183</link>
      <description>&lt;P&gt;A reply by:&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/142551"&gt;@neelrohit&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We have tamper protection as a feature, and if someone tries unauthorized access or attempts to disable the agent using the means which is not supposed to be(eg, disabling registry, taskkill commands etc.) Cortex XDR will generate prevention or detection alerts for the same. However, if you disable the agent using cytool commands, we do not get alerts. These events are, however, logged-in agent audit logs and can be forwarded as notifications or created as correlation rules to generate alerts.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 16:44:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-cortex-xdr-active-scanning-webinar-failed/m-p/539228#M4183</guid>
      <dc:creator>rtsedaka</dc:creator>
      <dc:date>2023-04-18T16:44:23Z</dc:date>
    </item>
  </channel>
</rss>

