<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XQL - list of processes, which  were not started/launched in the last XX days in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-list-of-processes-which-were-not-started-launched-in-the/m-p/553842#M4971</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/304482"&gt;@mavega&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this would help us in the part "malware flew under the radar". We also see the rare processes in the company and can investigate deeper, if we want.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your research!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Aug 2023 20:40:24 GMT</pubDate>
    <dc:creator>RFeyertag</dc:creator>
    <dc:date>2023-08-15T20:40:24Z</dc:date>
    <item>
      <title>XQL - list of processes, which  were not started/launched in the last XX days</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-list-of-processes-which-were-not-started-launched-in-the/m-p/553695#M4963</link>
      <description>&lt;P&gt;Hello dear community,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to have a list of processes which were not started/launched in the past XX days. I think it would be nice to know, which processes are brand new etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Will this work with XQL and how?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 21:24:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-list-of-processes-which-were-not-started-launched-in-the/m-p/553695#M4963</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-08-14T21:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: XQL - list of processes, which  were not started/launched in the last XX days</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-list-of-processes-which-were-not-started-launched-in-the/m-p/553823#M4970</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A id="link_7" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671" target="_self" aria-label="View Profile of RFeyertag"&gt;&lt;SPAN class=""&gt;RFeyertag&lt;/SPAN&gt;&lt;/A&gt;,&lt;/P&gt;
&lt;P&gt;Thanks for reaching out to our live community.&lt;/P&gt;
&lt;P&gt;We are looking into your inquiry and doing some research to provide you with the best possible response.&lt;/P&gt;
&lt;P&gt;Could you please elaborate a bit more? What is the use case for your inquiry?&lt;/P&gt;
&lt;P&gt;Please provide as many details as possible as there might a better approach on gathering the information you are looking for.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 18:56:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-list-of-processes-which-were-not-started-launched-in-the/m-p/553823#M4970</guid>
      <dc:creator>mavega</dc:creator>
      <dc:date>2023-08-15T18:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: XQL - list of processes, which  were not started/launched in the last XX days</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-list-of-processes-which-were-not-started-launched-in-the/m-p/553842#M4971</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/304482"&gt;@mavega&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this would help us in the part "malware flew under the radar". We also see the rare processes in the company and can investigate deeper, if we want.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your research!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 20:40:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-list-of-processes-which-were-not-started-launched-in-the/m-p/553842#M4971</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-08-15T20:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: XQL - list of processes, which  were not started/launched in the last XX days</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-list-of-processes-which-were-not-started-launched-in-the/m-p/554031#M4980</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class="UserName lia-user-name lia-user-rank-L4-Transporter lia-component-message-view-widget-author-username"&gt;&lt;A id="link_20" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671" target="_self" aria-label="View Profile of RFeyertag"&gt;&lt;SPAN class=""&gt;RFeyertag,&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L4-Transporter lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;We are still looking into this one, not sure Cortex works that way, but if you have Host Insight add-on maybe you can try the below script, it might not provide the non running processes but it will show the state of them and you might be able to sort them out (script is for 30 days but you can change it):&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="c-mrkdwn__pre" data-stringify-type="pre"&gt;preset = host_inventory_services 
| alter More_Than_30D = if((timestamp_diff(current_time(),report_timestamp  ,"day")&amp;gt;=30) , "True", "False")
| filter (More_Than_30D != """False""") 
| filter started = "false"
| fields  service_name ,report_timestamp , More_Than_30D , service_state , service_type , endpoint_name , started 
| dedup service_name &lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 18:42:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-list-of-processes-which-were-not-started-launched-in-the/m-p/554031#M4980</guid>
      <dc:creator>mavega</dc:creator>
      <dc:date>2023-08-16T18:42:56Z</dc:date>
    </item>
  </channel>
</rss>

