<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Malware Scan Results Vs Alerts Created in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-results-vs-alerts-created/m-p/561172#M5314</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I'm just wondering if someone can help me understand, why&amp;nbsp; the results of a malware scan (i.e. 19 malicious files found) doesn't reflect the amount of alerts created. I'd assume there would be 19 malicious files as stated, with an alert for each?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;As you can see in the example below, the scan yielded 19 malicious files in the results:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BojanTotic_1-1696977019013.png" style="width: 869px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54291iA026EF41E46E3E67/image-dimensions/869x209/is-moderation-mode/true?v=v2" width="869" height="209" role="button" title="BojanTotic_1-1696977019013.png" alt="BojanTotic_1-1696977019013.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;When I click on show alerts, it takes me to the below screenshot.. but all I see is 8 alerts about 7 files.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Should there be more alerts specific to each malicious files found? And if not, where would I ensure that all 19 files are accounted for in a trigger?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BojanTotic_2-1696977165798.png" style="width: 791px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54292iC948562C63391440/image-dimensions/791x261/is-moderation-mode/true?v=v2" width="791" height="261" role="button" title="BojanTotic_2-1696977165798.png" alt="BojanTotic_2-1696977165798.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the help in advance!&lt;/P&gt;
&lt;P&gt;Bojan&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Oct 2023 22:33:36 GMT</pubDate>
    <dc:creator>Bojan-Totic</dc:creator>
    <dc:date>2023-10-10T22:33:36Z</dc:date>
    <item>
      <title>Malware Scan Results Vs Alerts Created</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-results-vs-alerts-created/m-p/561172#M5314</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I'm just wondering if someone can help me understand, why&amp;nbsp; the results of a malware scan (i.e. 19 malicious files found) doesn't reflect the amount of alerts created. I'd assume there would be 19 malicious files as stated, with an alert for each?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;As you can see in the example below, the scan yielded 19 malicious files in the results:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BojanTotic_1-1696977019013.png" style="width: 869px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54291iA026EF41E46E3E67/image-dimensions/869x209/is-moderation-mode/true?v=v2" width="869" height="209" role="button" title="BojanTotic_1-1696977019013.png" alt="BojanTotic_1-1696977019013.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;When I click on show alerts, it takes me to the below screenshot.. but all I see is 8 alerts about 7 files.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Should there be more alerts specific to each malicious files found? And if not, where would I ensure that all 19 files are accounted for in a trigger?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BojanTotic_2-1696977165798.png" style="width: 791px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54292iC948562C63391440/image-dimensions/791x261/is-moderation-mode/true?v=v2" width="791" height="261" role="button" title="BojanTotic_2-1696977165798.png" alt="BojanTotic_2-1696977165798.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the help in advance!&lt;/P&gt;
&lt;P&gt;Bojan&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 22:33:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-results-vs-alerts-created/m-p/561172#M5314</guid>
      <dc:creator>Bojan-Totic</dc:creator>
      <dc:date>2023-10-10T22:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Malware Scan Results Vs Alerts Created</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-results-vs-alerts-created/m-p/561178#M5316</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/213553"&gt;@Bojan-Totic&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out to the Live Community. I see in the second screenshot there is a filter applied, could you please try to change search field as host and see if you are able to see all the alerts for 19 files as seen in the first screenshot? Please let us know if this resolves our issue. Thank you.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you. &lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 01:47:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-results-vs-alerts-created/m-p/561178#M5316</guid>
      <dc:creator>abdrahman</dc:creator>
      <dc:date>2023-10-11T01:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: Malware Scan Results Vs Alerts Created</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-results-vs-alerts-created/m-p/561259#M5318</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/213553"&gt;@Bojan-Totic&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is expected, because of deduplication period i.e.&amp;nbsp;&lt;SPAN&gt;The amount of time in which additional alerts for the same activity or behavior are suppressed before&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="phrase"&gt;Cortex XDR&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;raises another alert&amp;nbsp;&lt;/SPAN&gt;and this is avoid flooding with so many alerts. Therefore in the alert triggered it shows number of time similar activity/alert triggered. As can be seen from your screenshot +4, +6 and +2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Likewise, sharing this screenshot for reference. In this case since those 85 alerts were for the same file/activity/behavior, hence instead of triggering 85 alerts it mentions about the related alerts from the last hour.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PiyushKohli_0-1697022546894.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54324iA3244533233072F4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PiyushKohli_0-1697022546894.png" alt="PiyushKohli_0-1697022546894.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 11:13:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-results-vs-alerts-created/m-p/561259#M5318</guid>
      <dc:creator>PiyushKohli</dc:creator>
      <dc:date>2023-10-11T11:13:47Z</dc:date>
    </item>
    <item>
      <title>Re: Malware Scan Results Vs Alerts Created</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-results-vs-alerts-created/m-p/561287#M5319</link>
      <description>&lt;P&gt;Oh okay, thank you that helps!&lt;BR /&gt;&lt;BR /&gt;Do you see any pitfalls of not being able to see all referenced 19 malicious files in that moment, although they somehow share similar behavior/characteristics? My worry is essentially not getting the full picture during the response/remediation phase.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards,&lt;/P&gt;
&lt;P&gt;Bojan&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 14:04:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-results-vs-alerts-created/m-p/561287#M5319</guid>
      <dc:creator>Bojan-Totic</dc:creator>
      <dc:date>2023-10-11T14:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: Malware Scan Results Vs Alerts Created</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-results-vs-alerts-created/m-p/561288#M5320</link>
      <description>&lt;P&gt;Hey Abraham,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the response. Clearing the filter and adding the host does not show all 19 files. I believe the deduplication period that Piyush mentioned makes sense!&lt;BR /&gt;&lt;BR /&gt;Appreciate your time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards,&lt;/P&gt;
&lt;P&gt;Bojan&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 14:12:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-results-vs-alerts-created/m-p/561288#M5320</guid>
      <dc:creator>Bojan-Totic</dc:creator>
      <dc:date>2023-10-11T14:12:41Z</dc:date>
    </item>
  </channel>
</rss>

