<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The Cortex XDR not installed still incident getting generated in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/the-cortex-xdr-not-installed-still-incident-getting-generated/m-p/567034#M5605</link>
    <description>&lt;P&gt;We have observed incident on the server in which Cortex XDR is not installed. The system is only present in the asset inventory. How is this possible, on what basis incident is getting generated?&lt;/P&gt;
&lt;P&gt;Incident Name:&amp;nbsp;&lt;STRONG&gt;Multiple Rare LOLBIN Process Executions by User&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Fri, 24 Nov 2023 14:54:08 GMT</pubDate>
    <dc:creator>Shinde_Dipak</dc:creator>
    <dc:date>2023-11-24T14:54:08Z</dc:date>
    <item>
      <title>The Cortex XDR not installed still incident getting generated</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/the-cortex-xdr-not-installed-still-incident-getting-generated/m-p/567034#M5605</link>
      <description>&lt;P&gt;We have observed incident on the server in which Cortex XDR is not installed. The system is only present in the asset inventory. How is this possible, on what basis incident is getting generated?&lt;/P&gt;
&lt;P&gt;Incident Name:&amp;nbsp;&lt;STRONG&gt;Multiple Rare LOLBIN Process Executions by User&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 14:54:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/the-cortex-xdr-not-installed-still-incident-getting-generated/m-p/567034#M5605</guid>
      <dc:creator>Shinde_Dipak</dc:creator>
      <dc:date>2023-11-24T14:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: The Cortex XDR not installed still incident getting generated</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/the-cortex-xdr-not-installed-still-incident-getting-generated/m-p/567277#M5612</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&amp;nbsp;&lt;A id="link_7" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/337761" target="_self" aria-label="View Profile of Shinde_Dipak"&gt;Shinde_Dipak,&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;'Multiple Rare LOLBIN Process Executions by User' alert is generated by XDR Analytics were detected. Reference&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR-Analytics-Alert-Reference/Multiple-Rare-LOLBIN-Process-Executions-by-User" target="_self"&gt;Multiple Rare LOLBIN Process Executions by User • Cortex XDR Analytics Alert Reference&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The source for this detection is data collected from the&amp;nbsp;XDR Agent with&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics-Concepts" target="_self"&gt; Identity Analytics&lt;/A&gt; enabled. However, customers can take advantage&amp;nbsp;of analytics network or identity detectors on a host in the absence of the XDR agent if additional network and identity data sources (&lt;SPAN&gt;Cloud Identity Engine, Azure etc.)&lt;/SPAN&gt; are onboarded directly into Cortex XDR.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example, in addition to the agent, Cortex XDR can ingest PAN NGFW&amp;nbsp;&lt;SPAN&gt;Enhanced application logs (EAL) and&lt;/SPAN&gt; Third-party authentication service logs with the&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/License-Monitoring" target="_self"&gt; Pro GB or Cloud license&lt;/A&gt; to detect threats by collecting and analyzing cloud logs. Its analytics detectors examine cloud audit, flow, and identity logs to baseline behavior.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reference&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Ingest-Data-from-Next-Generation-Firewall" target="_blank" rel="noopener"&gt;Ingest Data from Next-Generation Firewall • Cortex XDR Pro Administrator Guide • Reader • Palo Alto Networks documentation portal&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Visibility-of-Logs-and-Alerts-from-External-Sources" target="_blank" rel="noopener"&gt;Visibility of Logs and Alerts from External Sources • Cortex XDR Pro Administrator Guide • Reader • Palo Alto Networks documentation portal&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics" target="_blank" rel="noopener"&gt;Analytics • Cortex XDR Pro Administrator Guide • Reader • Palo Alto Networks documentation portal&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To investigate, concerning the endpoint data collection gathered to stitch an alert,&amp;nbsp;review the Debug alert data collected from the event for analysis:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG data-aura-rendered-by="230:5538;a"&gt;Collect Debug data from Incidents Tab&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL data-aura-rendered-by="230:5538;a"&gt;
&lt;LI&gt;Go To Incidents Tab and select the Incident that you want to Debug.&lt;/LI&gt;
&lt;LI&gt;Alt+ Right Click on the Incident and select Download Debug Data&lt;/LI&gt;
&lt;/OL&gt;
&lt;DIV id="tinyMceEditor_3d8e56a6a0558ejtalton_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditor_3d8e56a6a0558ejtalton_2" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jtalton_3-1701120088857.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55449i99A037DD34AED1D3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jtalton_3-1701120088857.png" alt="jtalton_3-1701120088857.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-aura-rendered-by="230:5538;a"&gt;&lt;STRONG&gt;Collect Debug Alert data From Alerts page&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL data-aura-rendered-by="230:5538;a"&gt;
&lt;LI&gt;&amp;nbsp;Go to the Alert and press Alt+ Right Click to select Debug Alert&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jtalton_4-1701120135457.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55450iCC9B9109DE21C483/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jtalton_4-1701120135457.png" alt="jtalton_4-1701120135457.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;OL start="2" data-aura-rendered-by="230:5538;a"&gt;
&lt;LI&gt;It will open another window with Debug logs. Click on 'Copy Log' and view the logs for analysis.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;If you found this answer helpful, please select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 21:40:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/the-cortex-xdr-not-installed-still-incident-getting-generated/m-p/567277#M5612</guid>
      <dc:creator>jtalton</dc:creator>
      <dc:date>2023-11-27T21:40:56Z</dc:date>
    </item>
  </channel>
</rss>

