<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows Anti-Malware Scan Interface (AMSI) and Cortex XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-anti-malware-scan-interface-amsi-and-cortex-xdr/m-p/563124#M5426</link>
    <description>&lt;P&gt;Hey community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm curious if anyone's had experience with integrating AMSI with Sharepoint servers and how Cortex XDR works into all of that. I am curious also, if AMSI needs to be enabled or if it's recommended to be disabled. Any current configuration documentation I find references Microsoft Defender and we've disabled that running XDR alone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/sharepoint/security-for-sharepoint-server/configure-amsi-integration" target="_blank"&gt;Configure AMSI integration with SharePoint Server - SharePoint Server | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a support case open for the same question but wanted to reach out here as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks everyone!&lt;/P&gt;</description>
    <pubDate>Wed, 25 Oct 2023 15:24:14 GMT</pubDate>
    <dc:creator>CraigV123</dc:creator>
    <dc:date>2023-10-25T15:24:14Z</dc:date>
    <item>
      <title>Windows Anti-Malware Scan Interface (AMSI) and Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-anti-malware-scan-interface-amsi-and-cortex-xdr/m-p/563124#M5426</link>
      <description>&lt;P&gt;Hey community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm curious if anyone's had experience with integrating AMSI with Sharepoint servers and how Cortex XDR works into all of that. I am curious also, if AMSI needs to be enabled or if it's recommended to be disabled. Any current configuration documentation I find references Microsoft Defender and we've disabled that running XDR alone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/sharepoint/security-for-sharepoint-server/configure-amsi-integration" target="_blank"&gt;Configure AMSI integration with SharePoint Server - SharePoint Server | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a support case open for the same question but wanted to reach out here as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks everyone!&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 15:24:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-anti-malware-scan-interface-amsi-and-cortex-xdr/m-p/563124#M5426</guid>
      <dc:creator>CraigV123</dc:creator>
      <dc:date>2023-10-25T15:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Anti-Malware Scan Interface (AMSI) and Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-anti-malware-scan-interface-amsi-and-cortex-xdr/m-p/563401#M5435</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/112301"&gt;@CraigV123&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;I do not have experience for AMSI integration with Sharepoint. But XDR do collect AMSI content scan events and use it for detection purposes. You can use below example XQL query to fetch AMSI data.&lt;/P&gt;
&lt;P&gt;preset = xdr_event_log &lt;BR /&gt;| filter lowercase(action_evtlog_description) contains "amsi"&lt;BR /&gt;| filter lowercase(action_evtlog_username) not contains "system"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Similarly we also use Scriptblock logging to deobfuscate powershell scripts. Please refer to below video on this topic.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/cortex-xdr-how-to-video-script-block-query-and-bioc/ta-p/510469" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/cortex-xdr-how-to-video-script-block-query-and-bioc/ta-p/510469&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We do not recommend to disable AMSI. Please let us know if you have additional questions.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 16:04:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-anti-malware-scan-interface-amsi-and-cortex-xdr/m-p/563401#M5435</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2023-10-27T16:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Anti-Malware Scan Interface (AMSI) and Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-anti-malware-scan-interface-amsi-and-cortex-xdr/m-p/577468#M6074</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/112301"&gt;@CraigV123&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We're facing the same challenge. The integration of the AMSI SharePoint feature with Cortex XDR seems not to work.&lt;/P&gt;
&lt;P&gt;How did you deal with it? Do you enable or disable the feature?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I understand it, Cortex only collects AMSI events that are related to a script engine like PowerShell.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 08:03:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-anti-malware-scan-interface-amsi-and-cortex-xdr/m-p/577468#M6074</guid>
      <dc:creator>Rocky-25</dc:creator>
      <dc:date>2024-02-16T08:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Anti-Malware Scan Interface (AMSI) and Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-anti-malware-scan-interface-amsi-and-cortex-xdr/m-p/577499#M6080</link>
      <description>&lt;P&gt;Hey Rocky,&lt;/P&gt;
&lt;P&gt;For the time being, we actually did leave it disabled. We also only had the Prevent license model of XDR at the time and since upgraded to Pro so there's a lot more visibility into the SharePoint environment if something nefarious does happen. I reached out to Microsoft also, without high expectations, and did not receive a lot of help from them either.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;XDR Pro, coupled with our other defense layers, provide good insight to those hosts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 12:32:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/windows-anti-malware-scan-interface-amsi-and-cortex-xdr/m-p/577499#M6080</guid>
      <dc:creator>CraigV123</dc:creator>
      <dc:date>2024-02-16T12:32:32Z</dc:date>
    </item>
  </channel>
</rss>

