<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wildfire Malware Alert in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-malware-alert/m-p/563094#M5423</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/317230"&gt;@nithin.k&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is to be expected given the deduplication period, which is the amount of time Cortex XDR waits before raising another warning for the same activity or behavior in order to prevent an alert overload. As a result, the alert triggered displays the frequency of comparable activity or alert triggering.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm also sending this screenshot in case it helps. In this instance, the alert system highlights the relevant alerts from the previous hour rather than raising 85 alarms because those 85 warnings were for the same file, activity, or conduct.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dbahuguna_0-1698224144381.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54665iE766F0CE81759C54/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="dbahuguna_0-1698224144381.png" alt="dbahuguna_0-1698224144381.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Oct 2023 10:04:52 GMT</pubDate>
    <dc:creator>dbahuguna</dc:creator>
    <dc:date>2023-10-25T10:04:52Z</dc:date>
    <item>
      <title>Wildfire Malware Alert</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-malware-alert/m-p/562375#M5382</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For testing purpose, i triggered an incident by trying to execute a malicious file. The execution was successfully blocked and a "Wildfire Malware" alert was created in XDR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried executing the file once more. The execution was blocked again, but this time alert was not created in XDR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What could be the reason?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I checked the "Events" section under the XDR agent tray icon in the endpoint. There i am able to see an event for the execution. But in XDR alert is not generating.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Nithin&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 09:03:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-malware-alert/m-p/562375#M5382</guid>
      <dc:creator>nithin.k</dc:creator>
      <dc:date>2023-10-19T09:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Malware Alert</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-malware-alert/m-p/562408#M5385</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/317230"&gt;@nithin.k&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the functionality of Cortex XDR, it will not generate a new incident for the same alert type or file run from the same location. However, you will see another alert added to the same incident generated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Moreover, as this is with respect to an incident handling with which if you require more assistance or in order to investigate it further, as this is a public discussion forum my suggestion would be to refer to your Customer Success team or TAC by opening a ticket through our&amp;nbsp;&lt;A href="https://support.paloaltonetworks.com/Support/Index" target="_blank" rel="nofollow noopener noreferrer"&gt;support portal&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Feel free to write back if you have further query.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 12:49:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-malware-alert/m-p/562408#M5385</guid>
      <dc:creator>dbahuguna</dc:creator>
      <dc:date>2023-10-19T12:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Malware Alert</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-malware-alert/m-p/562426#M5387</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/317230"&gt;@nithin.k&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Similar query was posted on LC few days back and as shared by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/221362"&gt;@dbahuguna&lt;/a&gt;&amp;nbsp;this is because of deduplication XDR won't&lt;SPAN&gt;&amp;nbsp;not generate a new incident for the same alert type or file run from the same location&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may refer to this &lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/malware-scan-results-vs-alerts-created/m-p/561259#M5318" target="_self"&gt;Post&lt;/A&gt; for info around the same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Feel free to write back if you have further query.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 13:56:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-malware-alert/m-p/562426#M5387</guid>
      <dc:creator>PiyushKohli</dc:creator>
      <dc:date>2023-10-19T13:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Malware Alert</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-malware-alert/m-p/562517#M5389</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/221362"&gt;@dbahuguna&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I didn't ask about incident.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you can see my query again, i was asking about alerts. The second time execution of the same malware file didn't trigger an alert in XDR. That is my query.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The execution was successfully blocked by XDR agent but alert was not generated in XDR. That is the problem here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Nithin&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 05:57:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-malware-alert/m-p/562517#M5389</guid>
      <dc:creator>nithin.k</dc:creator>
      <dc:date>2023-10-20T05:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Malware Alert</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-malware-alert/m-p/563094#M5423</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/317230"&gt;@nithin.k&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is to be expected given the deduplication period, which is the amount of time Cortex XDR waits before raising another warning for the same activity or behavior in order to prevent an alert overload. As a result, the alert triggered displays the frequency of comparable activity or alert triggering.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm also sending this screenshot in case it helps. In this instance, the alert system highlights the relevant alerts from the previous hour rather than raising 85 alarms because those 85 warnings were for the same file, activity, or conduct.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dbahuguna_0-1698224144381.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54665iE766F0CE81759C54/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="dbahuguna_0-1698224144381.png" alt="dbahuguna_0-1698224144381.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 10:04:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-malware-alert/m-p/563094#M5423</guid>
      <dc:creator>dbahuguna</dc:creator>
      <dc:date>2023-10-25T10:04:52Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Malware Alert</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-malware-alert/m-p/563101#M5425</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/221362"&gt;@dbahuguna&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 10:14:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wildfire-malware-alert/m-p/563101#M5425</guid>
      <dc:creator>nithin.k</dc:creator>
      <dc:date>2023-10-25T10:14:40Z</dc:date>
    </item>
  </channel>
</rss>

