<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why there are no related alerts on scanned malicious files. in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/why-there-are-no-related-alerts-on-scanned-malicious-files/m-p/545555#M4527</link>
    <description>&lt;P&gt;Hi, we have recently malware scanned an endpoint and upon checking the results, it appears that there were 3 malicious files on the host.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-06-10 15_39_58-Action Center - Cortex XDR.png" style="width: 648px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50816i41E8D1257E754EB5/image-dimensions/648x81/is-moderation-mode/true?v=v2" width="648" height="81" role="button" title="2023-06-10 15_39_58-Action Center - Cortex XDR.png" alt="2023-06-10 15_39_58-Action Center - Cortex XDR.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Now, I tried to right click and view related alerts on the 3 malicious files and it just shows nothing. What's weird about this is it showing MD5 hashes on External ID field. I checked those hashes via ThreatVault and VirusTotal and it doesn't give any results.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aaronquiamco_0-1686382887819.png" style="width: 781px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50817i2BD56021935EE941/image-dimensions/781x203/is-moderation-mode/true?v=v2" width="781" height="203" role="button" title="aaronquiamco_0-1686382887819.png" alt="aaronquiamco_0-1686382887819.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Now my question is how are we suppose to track the 3 malicious files as per malware scan when we have no idea what it is and Cortex showing not enough insight. Checking the historical incidents on this host in regards of malicious files, I only see one WildFire related incident for the past few months.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Sat, 10 Jun 2023 07:54:08 GMT</pubDate>
    <dc:creator>aaronquiamco</dc:creator>
    <dc:date>2023-06-10T07:54:08Z</dc:date>
    <item>
      <title>Why there are no related alerts on scanned malicious files.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/why-there-are-no-related-alerts-on-scanned-malicious-files/m-p/545555#M4527</link>
      <description>&lt;P&gt;Hi, we have recently malware scanned an endpoint and upon checking the results, it appears that there were 3 malicious files on the host.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-06-10 15_39_58-Action Center - Cortex XDR.png" style="width: 648px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50816i41E8D1257E754EB5/image-dimensions/648x81/is-moderation-mode/true?v=v2" width="648" height="81" role="button" title="2023-06-10 15_39_58-Action Center - Cortex XDR.png" alt="2023-06-10 15_39_58-Action Center - Cortex XDR.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Now, I tried to right click and view related alerts on the 3 malicious files and it just shows nothing. What's weird about this is it showing MD5 hashes on External ID field. I checked those hashes via ThreatVault and VirusTotal and it doesn't give any results.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aaronquiamco_0-1686382887819.png" style="width: 781px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50817i2BD56021935EE941/image-dimensions/781x203/is-moderation-mode/true?v=v2" width="781" height="203" role="button" title="aaronquiamco_0-1686382887819.png" alt="aaronquiamco_0-1686382887819.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Now my question is how are we suppose to track the 3 malicious files as per malware scan when we have no idea what it is and Cortex showing not enough insight. Checking the historical incidents on this host in regards of malicious files, I only see one WildFire related incident for the past few months.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jun 2023 07:54:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/why-there-are-no-related-alerts-on-scanned-malicious-files/m-p/545555#M4527</guid>
      <dc:creator>aaronquiamco</dc:creator>
      <dc:date>2023-06-10T07:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: Why there are no related alerts on scanned malicious files.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/why-there-are-no-related-alerts-on-scanned-malicious-files/m-p/545559#M4529</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/297211"&gt;@aaronquiamco&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community.&lt;BR /&gt;&lt;BR /&gt;By default the Cortex XDR will generate alerts with action Detected(Scanned) whenever it scans a malicious file. As a result, you should have the alerts present there. It seems that you have a filter applied on External ID which is not clear enough to describe whether you received the alert or not. You can use the filter for endpoint name and alert action for the use case as shown below:&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="100%"&gt;Host= &amp;lt;Hostname&amp;gt; AND Alert Source= XDR Agent AND ACTION =Detected(Scanned)&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the above still does not yield any output for you, it is probable that there is an Alert Exclusion rule created for the parameters which will exclude and suppress alerts either from the endpoint or for the scanned as an action. Example of an alert exclusion configuration could be as shown below in the image.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps. Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-06-10 at 8.13.28 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50819iADA078507059EF85/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-06-10 at 8.13.28 PM.png" alt="Screenshot 2023-06-10 at 8.13.28 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jun 2023 12:14:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/why-there-are-no-related-alerts-on-scanned-malicious-files/m-p/545559#M4529</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-06-10T12:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: Why there are no related alerts on scanned malicious files.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/why-there-are-no-related-alerts-on-scanned-malicious-files/m-p/545564#M4531</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I really need help on this one as we have no idea where we can pull out the 3 malicious files via Malware Scan option.&lt;/P&gt;
&lt;P&gt;I highly doubt there was alert exclusions made on the host as this is a workstation and needs to be monitored always. I have also checked alert exclusions page and there were none related to the endpoint we malware scanned.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have checked through this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aaronquiamco_0-1686405643509.png" style="width: 667px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50820iF301E3FFFD2CED48/image-dimensions/667x122/is-moderation-mode/true?v=v2" width="667" height="122" role="button" title="aaronquiamco_0-1686405643509.png" alt="aaronquiamco_0-1686405643509.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;And set additional search parameters but it still did not show anything:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aaronquiamco_1-1686405696766.png" style="width: 681px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50821i0E173BB98DF0BEEB/image-dimensions/681x214/is-moderation-mode/true?v=v2" width="681" height="214" role="button" title="aaronquiamco_1-1686405696766.png" alt="aaronquiamco_1-1686405696766.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now may I ask what is the best way for us to approach this kind of scenario? We don't know if the malware scan result is a false positive or there's a legitimate malicious files on the host itself.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jun 2023 14:02:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/why-there-are-no-related-alerts-on-scanned-malicious-files/m-p/545564#M4531</guid>
      <dc:creator>aaronquiamco</dc:creator>
      <dc:date>2023-06-10T14:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Why there are no related alerts on scanned malicious files.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/why-there-are-no-related-alerts-on-scanned-malicious-files/m-p/545565#M4532</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/297211"&gt;@aaronquiamco&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please remove the External ID from the filter and try using the filter mentioned in the previous response. Simply use:&amp;nbsp;&lt;BR /&gt;Host=&amp;lt;Endpoint Name&amp;gt; AND and action= Detected(Scanned)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please see if it gives you results. I am assuming that there could be issue in the External ID filter.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If none of the above works, please retrieve the Tech Support files from the endpoint and provide the tenant information from the About page and open a case with Palo Alto networks support for break fix.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jun 2023 14:19:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/why-there-are-no-related-alerts-on-scanned-malicious-files/m-p/545565#M4532</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-06-10T14:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why there are no related alerts on scanned malicious files.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/why-there-are-no-related-alerts-on-scanned-malicious-files/m-p/545865#M4561</link>
      <description>&lt;P&gt;May I get the link for the&amp;nbsp;&lt;SPAN&gt;open a case section with Palo Alto networks support.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 21:23:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/why-there-are-no-related-alerts-on-scanned-malicious-files/m-p/545865#M4561</guid>
      <dc:creator>aaronquiamco</dc:creator>
      <dc:date>2023-06-13T21:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: Why there are no related alerts on scanned malicious files.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/why-there-are-no-related-alerts-on-scanned-malicious-files/m-p/545898#M4564</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/297211"&gt;@aaronquiamco&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is &lt;A href="https://support.paloaltonetworks.com/" target="_blank"&gt;https://support.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 03:06:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/why-there-are-no-related-alerts-on-scanned-malicious-files/m-p/545898#M4564</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-06-14T03:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why there are no related alerts on scanned malicious files.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/why-there-are-no-related-alerts-on-scanned-malicious-files/m-p/1221288#M7940</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/297211"&gt;@aaronquiamco&lt;/a&gt; , hope you are doing well. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I encounter the same as well. By any chance, can you share the solution if you opened a case with TAC?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 06:53:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/why-there-are-no-related-alerts-on-scanned-malicious-files/m-p/1221288#M7940</guid>
      <dc:creator>EdmarFrancis</dc:creator>
      <dc:date>2025-02-21T06:53:33Z</dc:date>
    </item>
  </channel>
</rss>

