<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR don't alert when using WinPeas.bat in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-don-t-alert-when-using-winpeas-bat/m-p/541820#M4323</link>
    <description>&lt;P&gt;Good morning,&lt;BR /&gt;We have noticed that when using LinPEAS on Linux systems, Cortex XDR reacts, blocks and alerts. However, using WinPEAS bat script on Windows systems is not detected by Cortex.&amp;nbsp;However winpeas.exe is blocked immediately.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For testing purposes we used linpeas.sh and winpeas.bat from:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/carlospolop/PEASS-ng" target="_blank"&gt;carlospolop/PEASS-ng: PEASS - Privilege Escalation Awesome Scripts SUITE (with colors) (github.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Why Cortex doesn't react when malicious .bat script is used?&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Thu, 11 May 2023 07:11:05 GMT</pubDate>
    <dc:creator>wbpdki</dc:creator>
    <dc:date>2023-05-11T07:11:05Z</dc:date>
    <item>
      <title>Cortex XDR don't alert when using WinPeas.bat</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-don-t-alert-when-using-winpeas-bat/m-p/541820#M4323</link>
      <description>&lt;P&gt;Good morning,&lt;BR /&gt;We have noticed that when using LinPEAS on Linux systems, Cortex XDR reacts, blocks and alerts. However, using WinPEAS bat script on Windows systems is not detected by Cortex.&amp;nbsp;However winpeas.exe is blocked immediately.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For testing purposes we used linpeas.sh and winpeas.bat from:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/carlospolop/PEASS-ng" target="_blank"&gt;carlospolop/PEASS-ng: PEASS - Privilege Escalation Awesome Scripts SUITE (with colors) (github.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Why Cortex doesn't react when malicious .bat script is used?&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 07:11:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-don-t-alert-when-using-winpeas-bat/m-p/541820#M4323</guid>
      <dc:creator>wbpdki</dc:creator>
      <dc:date>2023-05-11T07:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR don't alert when using WinPeas.bat</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-don-t-alert-when-using-winpeas-bat/m-p/542085#M4344</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/291016"&gt;@wbpdki&lt;/a&gt;, thank you for writing to Live Community.&lt;BR /&gt;&lt;BR /&gt;You're saying Winpeas.exe was blocked&amp;nbsp;&lt;SPAN&gt;immediately, but&amp;nbsp;WinPEAS bat script went undetected?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Please allow me some time to test it and get back to you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 14 May 2023 13:51:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-don-t-alert-when-using-winpeas-bat/m-p/542085#M4344</guid>
      <dc:creator>mavraham</dc:creator>
      <dc:date>2023-05-14T13:51:04Z</dc:date>
    </item>
  </channel>
</rss>

