<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic jusched.exe flagged as Threat by Behavioural Threat Protection in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/jusched-exe-flagged-as-threat-by-behavioural-threat-protection/m-p/564952#M5516</link>
    <description>&lt;P&gt;We are flooded by alerts from jusched.exe being flagged as Threat by Behavioural Threat Protection.&lt;/P&gt;
&lt;P&gt;Are exclusions the only way out to resolve?&lt;/P&gt;</description>
    <pubDate>Thu, 09 Nov 2023 09:40:05 GMT</pubDate>
    <dc:creator>RobertoPastorino</dc:creator>
    <dc:date>2023-11-09T09:40:05Z</dc:date>
    <item>
      <title>jusched.exe flagged as Threat by Behavioural Threat Protection</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/jusched-exe-flagged-as-threat-by-behavioural-threat-protection/m-p/564952#M5516</link>
      <description>&lt;P&gt;We are flooded by alerts from jusched.exe being flagged as Threat by Behavioural Threat Protection.&lt;/P&gt;
&lt;P&gt;Are exclusions the only way out to resolve?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 09:40:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/jusched-exe-flagged-as-threat-by-behavioural-threat-protection/m-p/564952#M5516</guid>
      <dc:creator>RobertoPastorino</dc:creator>
      <dc:date>2023-11-09T09:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: jusched.exe flagged as Threat by Behavioural Threat Protection</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/jusched-exe-flagged-as-threat-by-behavioural-threat-protection/m-p/565011#M5519</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/110751"&gt;@RobertoPastorino&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Exceptions should allow you to stop these prevention events from triggering the action. Also, if you thing that this is a false positive, then you even have a capability to get granular whitelisting by the help of Content Updates in next release. follow the steps below:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Create an alert exception on a profile where the affected endpoint is attached to a policy. Right click on alert &amp;gt; create alert exception.&lt;/LI&gt;
&lt;LI&gt;Now, right click on alert again and retrieve the alert dump data for the prevention event. Right click &amp;gt; Retrieve Additional Data&amp;gt; Retrieve Alert data. The alert dump should be collected in the action center&lt;/LI&gt;
&lt;LI&gt;Open a support case mentioning it as a security incident and for investigation to see if it can be whitelisted in a content update and attach the dump file to the case.&lt;/LI&gt;
&lt;LI&gt;Upon closer look and investigation and if deemed fit for global content whitelisting, the support team should confirm the content update which should resolve this issue.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Wait for the CU to be released and fetched by the endpoint and post that you can remove your created exception. The event should not be generated even without the exception after that.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 15:02:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/jusched-exe-flagged-as-threat-by-behavioural-threat-protection/m-p/565011#M5519</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-11-09T15:02:42Z</dc:date>
    </item>
    <item>
      <title>Re: jusched.exe flagged as Threat by Behavioural Threat Protection</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/jusched-exe-flagged-as-threat-by-behavioural-threat-protection/m-p/565018#M5521</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/110751"&gt;@RobertoPastorino&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope you are doing well. Thank you for reaching out to Live Community. I understand that this particular exe is getting detected by cortex XDR as behavioral threat. If you believe this is a legitimate application and is not detected falsely then we can create an exclusion for it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, you can create a support ticket and work with our support team and they will be happy to get the exe assisted and whitelist it globally. Thank you.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 15:42:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/jusched-exe-flagged-as-threat-by-behavioural-threat-protection/m-p/565018#M5521</guid>
      <dc:creator>abdrahman</dc:creator>
      <dc:date>2023-11-09T15:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: jusched.exe flagged as Threat by Behavioural Threat Protection</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/jusched-exe-flagged-as-threat-by-behavioural-threat-protection/m-p/565117#M5526</link>
      <description>&lt;P&gt;We are seeing the same alerts on Java updater jusched.exe. It started on the 9th of November:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN class="rule-inner-content"&gt;Behavioral threat detected (rule: other.malware_gen_mutex.zwzin)&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 08:12:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/jusched-exe-flagged-as-threat-by-behavioural-threat-protection/m-p/565117#M5526</guid>
      <dc:creator>adminglu</dc:creator>
      <dc:date>2023-11-10T08:12:57Z</dc:date>
    </item>
  </channel>
</rss>

