<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: True Positive / no incident / evasion / self made alerts helped to detect in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/true-positive-no-incident-evasion-self-made-alerts-helped-to/m-p/556849#M5097</link>
    <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/232716"&gt;@anlynch&lt;/a&gt;!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it would be nice if there could be a new rule for process which is not browser communicating to steamcommunity and/or t.me. And this rule should terminate this process.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because wildfire is not getting a 300 MB scr file to analyze. So it flew completely under the radar.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is one of the best evasion technique I've ever seen and I am a little bit proud that I detected it with much efort creating new rules to detect this peace of best stealer trojan.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Sep 2023 20:53:40 GMT</pubDate>
    <dc:creator>RFeyertag</dc:creator>
    <dc:date>2023-09-06T20:53:40Z</dc:date>
    <item>
      <title>True Positive / no incident / evasion / self made alerts helped to detect</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/true-positive-no-incident-evasion-self-made-alerts-helped-to/m-p/556567#M5087</link>
      <description>&lt;P&gt;Hello dear community,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;got an 2 hour infection on a fat client from this&amp;nbsp;&lt;A href="https://www.virustotal.com/gui/file/79e3e243726a8b29b4cf74576e364ce98dfadb5bd182d8d1ed55255e70defc2c/details" target="_blank"&gt;https://www.virustotal.com/gui/file/79e3e243726a8b29b4cf74576e364ce98dfadb5bd182d8d1ed55255e70defc2c/details&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This little guy was evading cortex xdr pro.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Whatch out and fill your blocklist, because they getting better and better.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Initial access was a google drive link and the pw protected rar/zip with about 120 MB size.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are interested with wich self made bioc we detected it let me know.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 16:15:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/true-positive-no-incident-evasion-self-made-alerts-helped-to/m-p/556567#M5087</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-09-05T16:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: True Positive / no incident / evasion / self made alerts helped to detect</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/true-positive-no-incident-evasion-self-made-alerts-helped-to/m-p/556765#M5093</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for sharing this with the community!&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 14:48:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/true-positive-no-incident-evasion-self-made-alerts-helped-to/m-p/556765#M5093</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-09-06T14:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: True Positive / no incident / evasion / self made alerts helped to detect</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/true-positive-no-incident-evasion-self-made-alerts-helped-to/m-p/556849#M5097</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/232716"&gt;@anlynch&lt;/a&gt;!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it would be nice if there could be a new rule for process which is not browser communicating to steamcommunity and/or t.me. And this rule should terminate this process.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because wildfire is not getting a 300 MB scr file to analyze. So it flew completely under the radar.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is one of the best evasion technique I've ever seen and I am a little bit proud that I detected it with much efort creating new rules to detect this peace of best stealer trojan.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 20:53:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/true-positive-no-incident-evasion-self-made-alerts-helped-to/m-p/556849#M5097</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-09-06T20:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: True Positive / no incident / evasion / self made alerts helped to detect</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/true-positive-no-incident-evasion-self-made-alerts-helped-to/m-p/557084#M5108</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;For Cortex XDR coverage information, please submit a TAC case and share your observation and workaround you did on the same for team to review and update.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2023 02:13:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/true-positive-no-incident-evasion-self-made-alerts-helped-to/m-p/557084#M5108</guid>
      <dc:creator>PiyushKohli</dc:creator>
      <dc:date>2023-09-08T02:13:45Z</dc:date>
    </item>
  </channel>
</rss>

