<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MSI stolen certificate alerts in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/msi-stolen-certificate-alerts/m-p/543117#M4412</link>
    <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/293537"&gt;@MRoberti&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LIVEcommunity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;The BTP rules you've mentioned are not a part of a bug or unintended action of Cortex XDR.&amp;nbsp; With that being said it would not be possible for me to determine if those alerts are false positive or not. They'd need to be investigated thoroughly.&amp;nbsp; I might suggest reaching out to &lt;A href="https://support.paloaltonetworks.com/Support/Index" target="_self"&gt;support&lt;/A&gt;&amp;nbsp;if you think these alerts are being created in error so they can examine the issue more closely.&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;I hope this information helps.&amp;nbsp; Have a great day!&lt;/P&gt;</description>
    <pubDate>Wed, 24 May 2023 01:37:33 GMT</pubDate>
    <dc:creator>anlynch</dc:creator>
    <dc:date>2023-05-24T01:37:33Z</dc:date>
    <item>
      <title>MSI stolen certificate alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/msi-stolen-certificate-alerts/m-p/543031#M4407</link>
      <description>&lt;P&gt;Today we started to get alerts for all our MSI laptops with the reason: "&lt;SPAN class="rule-inner-content"&gt;Behavioral threat detected (rule: msi_stolen_certificate.1)". The alerts trigger on the MSI software installed on the latops, like "MSI center", or "One dragon center".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="rule-inner-content"&gt;Are these false positives?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 11:41:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/msi-stolen-certificate-alerts/m-p/543031#M4407</guid>
      <dc:creator>MRoberti</dc:creator>
      <dc:date>2023-05-23T11:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: MSI stolen certificate alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/msi-stolen-certificate-alerts/m-p/543117#M4412</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/293537"&gt;@MRoberti&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LIVEcommunity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;The BTP rules you've mentioned are not a part of a bug or unintended action of Cortex XDR.&amp;nbsp; With that being said it would not be possible for me to determine if those alerts are false positive or not. They'd need to be investigated thoroughly.&amp;nbsp; I might suggest reaching out to &lt;A href="https://support.paloaltonetworks.com/Support/Index" target="_self"&gt;support&lt;/A&gt;&amp;nbsp;if you think these alerts are being created in error so they can examine the issue more closely.&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;I hope this information helps.&amp;nbsp; Have a great day!&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 01:37:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/msi-stolen-certificate-alerts/m-p/543117#M4412</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-05-24T01:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: MSI stolen certificate alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/msi-stolen-certificate-alerts/m-p/543158#M4415</link>
      <description>&lt;P&gt;We got the same alert for Intel Arc. Turns out Intel uses a component called Rivatuner in their setup and this is made by MSI. I guess leak of MSI certificates have caused cortex to consider all certificates from MSI as insecure? Would like to know more about this too.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 09:10:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/msi-stolen-certificate-alerts/m-p/543158#M4415</guid>
      <dc:creator>DavidStevens</dc:creator>
      <dc:date>2023-05-24T09:10:02Z</dc:date>
    </item>
  </channel>
</rss>

