<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XDR AV Scan Alerts/Incidents in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-av-scan-alerts-incidents/m-p/565021#M5522</link>
    <description>&lt;P&gt;Thanks for the information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please find the details below:&lt;/P&gt;
&lt;P&gt;The file verdict is "Benign LC".&lt;BR /&gt;Currently we are using 8.0.2 agent version on all endpoints.&lt;/P&gt;</description>
    <pubDate>Thu, 09 Nov 2023 17:06:05 GMT</pubDate>
    <dc:creator>RamyashreeMada</dc:creator>
    <dc:date>2023-11-09T17:06:05Z</dc:date>
    <item>
      <title>XDR AV Scan Alerts/Incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-av-scan-alerts-incidents/m-p/564783#M5503</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;During AV scan, everytime we are recieving cache file is detected from the different hosts and filename and Hash is same.&amp;nbsp;The file verdict is&amp;nbsp;&lt;SPAN&gt;Benign.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Help me how can I address this file. As it is a temporary file.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 09:58:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-av-scan-alerts-incidents/m-p/564783#M5503</guid>
      <dc:creator>RamyashreeMada</dc:creator>
      <dc:date>2023-11-08T09:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: XDR AV Scan Alerts/Incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-av-scan-alerts-incidents/m-p/564949#M5514</link>
      <description>&lt;P&gt;Hello Ramyashree,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you for writing to live community.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Could you please confirm whether you have checked which application is creating the cache file. Is that file creating in same location or different location?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 08:54:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-av-scan-alerts-incidents/m-p/564949#M5514</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2023-11-09T08:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: XDR AV Scan Alerts/Incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-av-scan-alerts-incidents/m-p/564951#M5515</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Microsoft Edge is creating the cache file and file creating on same location.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 09:06:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-av-scan-alerts-incidents/m-p/564951#M5515</guid>
      <dc:creator>RamyashreeMada</dc:creator>
      <dc:date>2023-11-09T09:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: XDR AV Scan Alerts/Incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-av-scan-alerts-incidents/m-p/564953#M5517</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206335"&gt;@RamyashreeMada&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;You can check with Microsoft or lookup the hash on Virus Total. As Hash and file name is same, you can create an exclusion or add it to the allow list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: Exclusion are done on the organizational decision.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 09:43:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-av-scan-alerts-incidents/m-p/564953#M5517</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2023-11-09T09:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: XDR AV Scan Alerts/Incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-av-scan-alerts-incidents/m-p/565014#M5520</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206335"&gt;@RamyashreeMada&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To just add to previous responses. There is a possibility that these cached files are removed after some time and by the time WF verdict is generated the endpoint fails to take the update in the local cache as the file is no more available. Also, I would like to know if you see the verdict as "Benign" or it says "Benign LC" ? Benign LC means that the WF is not confident on the verdict and lets Local analysis module examine the file and take a decision. However, local analysis engine declares this as a malware and hence the alert event. In these corner cases, making allow lists is good to go on SHA256 level.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In such cases you can report the verdict as incorrect and request re-examination of the file manually. The next time, the verdict should come as a solid verdict ("Benign" or "Malware").&amp;nbsp;&lt;BR /&gt;Though your query is slightly broad by nature, it would be narrowed down with some screenshots if you could be able to provide one.&amp;nbsp;The screenshots below are not same. Hence, you might want to check for this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-11-09 at 11.11.54 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55063i8B95FF0C5A94E3CC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-11-09 at 11.11.54 PM.png" alt="Screenshot 2023-11-09 at 11.11.54 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-11-09 at 11.13.56 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55064i13E2F88E3244838B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-11-09 at 11.13.56 PM.png" alt="Screenshot 2023-11-09 at 11.13.56 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another possibility, I would be more interested in knowing if this is constantly being faced by endpoints of a specific agent version or is it across? This is something that I am considering that the verdict is a solid "Benign" and not "Benign LC".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The reason being is that we have historically had a known issue on the endpoints where they failed to update the WF local cache on the endpoint and the solution was to upgrade XDR agents to the releases fixing this issue. I would also recommend taking up some alert dump files for the same SHA256 prevention event on the endpoint and a TSF from the endpoint and opening a support case for the same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps! Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 15:16:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-av-scan-alerts-incidents/m-p/565014#M5520</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-11-09T15:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: XDR AV Scan Alerts/Incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-av-scan-alerts-incidents/m-p/565021#M5522</link>
      <description>&lt;P&gt;Thanks for the information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please find the details below:&lt;/P&gt;
&lt;P&gt;The file verdict is "Benign LC".&lt;BR /&gt;Currently we are using 8.0.2 agent version on all endpoints.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 17:06:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-av-scan-alerts-incidents/m-p/565021#M5522</guid>
      <dc:creator>RamyashreeMada</dc:creator>
      <dc:date>2023-11-09T17:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: XDR AV Scan Alerts/Incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-av-scan-alerts-incidents/m-p/565023#M5523</link>
      <description>&lt;P&gt;Makes sense now. So, you need to either whitelist the hash for the time being and then report the verdict as incorrect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Steps below:&lt;/P&gt;
&lt;DIV id="tinyMceEditor_389321c5a1da18neelrohit_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rtaImage.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55066iC3090C5834B69822/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="rtaImage.png" alt="rtaImage.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Log into Cortex XDR/XSIAM; in the Incident with a wrong verdict for a sample&lt;/LI&gt;
&lt;LI&gt;Open detailed WildFire Analysis Report for the sample with the wrong verdict,&lt;/LI&gt;
&lt;LI&gt;Use a button “Report Verdict as Incorrect” to open a new menu. Add your comments with proper verdict chosen and simply mention in the comments as &lt;STRONG&gt;"This is categorised as Benign LC and seems to Edge cache files. Please review and verdict accordingly. I am selecting &amp;lt;your choice of verdict&amp;gt; verdict for now"&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Fill in the Verdict Change Request with a suggestion of a new verdict, your contact email, and a short explanation why you believe this verdict is incorrect. After the manual review is completed, a report will be sent to the email address you used here.&lt;/LI&gt;
&lt;LI&gt;Once the verdict is recieved and if found benign, then it is converted to solid benign and you can remove the SHA256 from your allowlist&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Hope this clarifies.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 17:21:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-av-scan-alerts-incidents/m-p/565023#M5523</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-11-09T17:21:52Z</dc:date>
    </item>
  </channel>
</rss>

