<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XDR Masquerading Incident in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-masquerading-incident/m-p/561404#M5325</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/308232"&gt;@aspatil&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Hash of the File : ee998a9733c34f4aaf428db9db744fa7c1249f6e2874f1e2c4f621938b8269f6&lt;BR /&gt;Microsoft Signed "msiexec.exe" process&lt;BR /&gt;&lt;BR /&gt;I'm not saying it is signed by cortex.&lt;BR /&gt;&lt;BR /&gt;My question is &lt;BR /&gt;Why the Microsoft signed EXE's are getting renamed and getting saved in "C:\Sysmon\" folder ?&lt;/P&gt;</description>
    <pubDate>Thu, 12 Oct 2023 09:47:55 GMT</pubDate>
    <dc:creator>CUppin</dc:creator>
    <dc:date>2023-10-12T09:47:55Z</dc:date>
    <item>
      <title>XDR Masquerading Incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-masquerading-incident/m-p/554968#M5041</link>
      <description>&lt;P&gt;From few days getting the alerts under the "Masquerading" alert name. when we analyzed we observed there is a .exe file creation in the sysmon folder with the long string "&lt;SPAN class="simple-value ng-star-inserted" title="C:\Sysmon\2BE609177094318EA49602B566942D95E6C81494161F8EC8A3AA6AE26FFCDD14F8F552F6EE998A9733C34F4AAF428DB9DB744FA7C1249F6E2874F1E2C4F621938B8269F64342DC2DF708853CEE37820C03BB3E66.exe"&gt;C:\Sysmon\2BE609177094318EA49602B566942D95E6C81494161F8EC8A3AA6AE26FFCDD14F8F552F6EE998A9733C34F4AAF428DB9DB744FA7C1249F6E2874F1E2C4F621938B8269F64342DC2DF708853CEE37820C03BB3E66.exe&lt;/SPAN&gt;" &lt;BR /&gt;&lt;BR /&gt;Initiator CMD:&lt;/P&gt;
&lt;DIV class="ag-cell-value ag-cell ag-cell-not-inline-editing ag-cell-normal-height ag-cell-focus" style="left: 3950px; width: 3200px;" tabindex="-1" role="gridcell" aria-colindex="19"&gt;
&lt;DIV class="secdo-cell-container"&gt;
&lt;DIV class="items ng-star-inserted"&gt;&lt;SPAN class="list-text-item items ng-star-inserted" title="C:\Windows\system32\msiexec.exe /V"&gt;&lt;SPAN class="list-text-item items ng-star-inserted" title="C:\Windows\system32\msiexec.exe /V"&gt; C:\Windows\system32\msiexec.exe /V &lt;BR /&gt;&lt;BR /&gt;Initiator Path&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;DIV class="ag-cell-value ag-cell ag-cell-not-inline-editing ag-cell-normal-height ag-cell-focus" style="left: 2600px; width: 1350px;" tabindex="-1" role="gridcell" aria-colindex="18"&gt;
&lt;DIV class="secdo-cell-container"&gt;
&lt;DIV class="items ng-star-inserted"&gt;&lt;SPAN class="list-text-item items ng-star-inserted" title="C:\Sysmon\2BE609177094318EA49602B566942D95E6C81494161F8EC8A3AA6AE26FFCDD14F8F552F6EE998A9733C34F4AAF428DB9DB744FA7C1249F6E2874F1E2C4F621938B8269F64342DC2DF708853CEE37820C03BB3E66.exe"&gt; C:\Sysmon\2BE609177094318EA49602B566942D95E6C81494161F8EC8A3AA6AE26FFCDD14F8F552F6EE998A9733C34F4AAF428DB9DB744FA7C1249F6E2874F1E2C4F621938B8269F64342DC2DF708853CEE37820C03BB3E66.exe &lt;BR /&gt;&lt;BR /&gt;XDR is detecting under the behavioral threat .&lt;BR /&gt;&lt;BR /&gt;Why exe files are creating under the "sysmon folder' with very long string.&lt;BR /&gt;&lt;BR /&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 02:28:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-masquerading-incident/m-p/554968#M5041</guid>
      <dc:creator>CUppin</dc:creator>
      <dc:date>2023-08-24T02:28:39Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Masquerading Incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-masquerading-incident/m-p/555719#M5056</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please help us with the hash value of&amp;nbsp;&lt;SPAN&gt;"C:\Sysmon\2BE609177094318EA49602B566942D95E6C81494161F8EC8A3AA6AE26FFCDD14F8F552F6EE998A9733C34F4AAF428DB9DB744FA7C1249F6E2874F1E2C4F621938B8269F64342DC2DF708853CEE37820C03BB3E66.exe"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What makes you think this is a XDR Application? Can you please check the App details and see if this app is signed by Palo Alto Networks?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 14:01:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-masquerading-incident/m-p/555719#M5056</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2023-08-29T14:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Masquerading Incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-masquerading-incident/m-p/561404#M5325</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/308232"&gt;@aspatil&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Hash of the File : ee998a9733c34f4aaf428db9db744fa7c1249f6e2874f1e2c4f621938b8269f6&lt;BR /&gt;Microsoft Signed "msiexec.exe" process&lt;BR /&gt;&lt;BR /&gt;I'm not saying it is signed by cortex.&lt;BR /&gt;&lt;BR /&gt;My question is &lt;BR /&gt;Why the Microsoft signed EXE's are getting renamed and getting saved in "C:\Sysmon\" folder ?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 09:47:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-masquerading-incident/m-p/561404#M5325</guid>
      <dc:creator>CUppin</dc:creator>
      <dc:date>2023-10-12T09:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Masquerading Incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-masquerading-incident/m-p/562284#M5374</link>
      <description>&lt;P&gt;Do you have file deletion protection enabled in your SysMon config xml?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 15:55:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-masquerading-incident/m-p/562284#M5374</guid>
      <dc:creator>eumbach</dc:creator>
      <dc:date>2023-10-18T15:55:30Z</dc:date>
    </item>
  </channel>
</rss>

