<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 'Failed Connections' alerts detected by XDR Analytics on 9 hosts  involving user nt authority\system in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/failed-connections-alerts-detected-by-xdr-analytics-on-9-hosts/m-p/539812#M4215</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/262549"&gt;@RajeshPremSingh&lt;/a&gt;,&amp;nbsp;thank you for writing to Live Community.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The 'failed connections' alert is an XDR Analytics alert that indicates that the&amp;nbsp;&lt;SPAN&gt;endpoint has failed connections to other endpoints that have been inactive for more than 24 hours, or that Cortex XDR Analytics has never seen on the network. You can read more about the alert and which investigative options you can potentially take&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR-Analytics-Alert-Reference/Failed-Connections" target="_self"&gt;here.&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;That said, I'm not entirely sure what you are asking. Could you please elaborate?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Could you elaborate on what is the ask here?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 23 Apr 2023 10:16:12 GMT</pubDate>
    <dc:creator>mavraham</dc:creator>
    <dc:date>2023-04-23T10:16:12Z</dc:date>
    <item>
      <title>'Failed Connections' alerts detected by XDR Analytics on 9 hosts  involving user nt authority\system</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/failed-connections-alerts-detected-by-xdr-analytics-on-9-hosts/m-p/539692#M4209</link>
      <description>&lt;P&gt;Hi we have multiple&amp;nbsp; failed connections from one host to several local IP&lt;/P&gt;
&lt;P&gt;&amp;nbsp; below cmd was in initiator&amp;nbsp;&lt;/P&gt;
&lt;P&gt;C:\WINDOWS\System32\svchost.exe -k NetSvcs -p -s iphlpsvc&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 12:18:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/failed-connections-alerts-detected-by-xdr-analytics-on-9-hosts/m-p/539692#M4209</guid>
      <dc:creator>RajeshPremSingh</dc:creator>
      <dc:date>2023-04-21T12:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: 'Failed Connections' alerts detected by XDR Analytics on 9 hosts  involving user nt authority\system</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/failed-connections-alerts-detected-by-xdr-analytics-on-9-hosts/m-p/539812#M4215</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/262549"&gt;@RajeshPremSingh&lt;/a&gt;,&amp;nbsp;thank you for writing to Live Community.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The 'failed connections' alert is an XDR Analytics alert that indicates that the&amp;nbsp;&lt;SPAN&gt;endpoint has failed connections to other endpoints that have been inactive for more than 24 hours, or that Cortex XDR Analytics has never seen on the network. You can read more about the alert and which investigative options you can potentially take&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR-Analytics-Alert-Reference/Failed-Connections" target="_self"&gt;here.&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;That said, I'm not entirely sure what you are asking. Could you please elaborate?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Could you elaborate on what is the ask here?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Apr 2023 10:16:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/failed-connections-alerts-detected-by-xdr-analytics-on-9-hosts/m-p/539812#M4215</guid>
      <dc:creator>mavraham</dc:creator>
      <dc:date>2023-04-23T10:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: 'Failed Connections' alerts detected by XDR Analytics on 9 hosts  involving user nt authority\system</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/failed-connections-alerts-detected-by-xdr-analytics-on-9-hosts/m-p/539837#M4216</link>
      <description>&lt;P&gt;we have an incident on Siem tools saying that 'Failed Connections' alerts were detected by XDR Analytics on 9 hosts involving user nt authority\system cmd: C:\WINDOWS\System32\svchost.exe -k NetSvcs -p -s iphlpsvc) Can anyone advise what these failed connections are&lt;/P&gt;
&lt;P&gt;failed remote ip: 10.20.0.3,10.40.0.6,10.1.0.8,192.168.106.8,192.168.50.11,10.144.40.15,192.168.2.15,10.10.10.19,10.5.36.19,192.168.128.21,192.168.0.26,10.144.40.27,10.5.38.28,192.168.86.30,10.144.40.32,192.168.86.35,192.168.16.36,192.168.2.37,10.219.134.40,192.168.0.43,192.168.0.44,10.67.136.49,192.168.16.50,192.168.22.50,192.168.14.52,10.144.40.53,192.168.0.54,10.1.2.50,192.168.68.56,10.5.166.57,192.168.32.65,192.168.16.70,10.0.0.74,192.168.12.81,192.168.2.82,192.168.0.84,192.168.0.92,192.168.4.106,192.168.30.108,10.30.150.113,10.69.6.114,10.10.0.117,192.168.30.118,192.168.30.121,10.0.0.122,172.24.62.139,192.168.68.140,192.168.30.146,10.36.74.148,192.168.30.149,10.10.10.154,192.168.30.166,10.5.38.167,10.211.76.192.168.3.161,192.168.1.165,192.168.1.182,10.148.85.189,192.168.31.195,192.168.11.214,172.17.13.218,192.168.1.225,192.168.199.227,192.168.1.229:64516,57866,50186,53264,57369,63517,56360,59945,55346,63539,53815,63032,64058,52794,59473,52307,64086,62039,58969,51806,54878,58466,51815,49262,53876,50805,50300,49276,62590,61567,52358,61065,49290,53903,50327,58541,53936,59570,59573,57529,50366,53957,63174,55495,62668,50896,49874,58075,49373,58590,64740,59111,54515,51444,64768,59141,&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 00:48:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/failed-connections-alerts-detected-by-xdr-analytics-on-9-hosts/m-p/539837#M4216</guid>
      <dc:creator>RajeshPremSingh</dc:creator>
      <dc:date>2023-04-24T00:48:50Z</dc:date>
    </item>
  </channel>
</rss>

