<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Large Upload(Generic) Microsoft Teams alerts in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/large-upload-generic-microsoft-teams-alerts/m-p/570372#M5764</link>
    <description>&lt;P&gt;in my case, when users start a meeting and sharing screen, the alert appear. but&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Dec 2023 17:19:22 GMT</pubDate>
    <dc:creator>tlmarques</dc:creator>
    <dc:date>2023-12-19T17:19:22Z</dc:date>
    <item>
      <title>Large Upload(Generic) Microsoft Teams alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/large-upload-generic-microsoft-teams-alerts/m-p/569705#M5723</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;We are receiving more alerts 'Large Upload (Generic)' generated by XDR Analytics from Microsoft Teams (&lt;SPAN class="text ng-star-inserted" title="ms-teams.exe"&gt;ms-teams.exe) and i checked the IPs -&amp;nbsp;&lt;SPAN&gt;Microsoft Corporation (ISP) and Domain -microsoft.com.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="text ng-star-inserted" title="ms-teams.exe"&gt;&lt;SPAN&gt;I need an answer to the following questions:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="text ng-star-inserted" title="ms-teams.exe"&gt;&lt;SPAN&gt;1. How the alerts are getting triggered&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="text ng-star-inserted" title="ms-teams.exe"&gt;&lt;SPAN&gt;2. How to Reduce it /mitigation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="text ng-star-inserted" title="ms-teams.exe"&gt;&lt;SPAN&gt;3. How to investigate it&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="text ng-star-inserted" title="ms-teams.exe"&gt;&lt;SPAN&gt;Pls help on it..... &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="text ng-star-inserted" title="ms-teams.exe"&gt;&lt;SPAN&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp; &amp;nbsp;#Large Upload (Generic)&amp;nbsp; &amp;nbsp; #alerts&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 13:37:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/large-upload-generic-microsoft-teams-alerts/m-p/569705#M5723</guid>
      <dc:creator>Vijisaga</dc:creator>
      <dc:date>2023-12-13T13:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: Large Upload(Generic) Microsoft Teams alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/large-upload-generic-microsoft-teams-alerts/m-p/569710#M5724</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/295108"&gt;@Vijisaga&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out to Palo Alto Networks Live community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below are the answers to your questions:&lt;/P&gt;
&lt;P&gt;1. How the alerts are getting triggered?&lt;/P&gt;
&lt;P&gt;The endpoint transferred large amounts of data to an external site using a different protocol from HTTP/s, FTP, or SMTP. (A specific detector is used for each of those protocols.) Cortex XDR Analytics assumes that data transfers out of your network are ordinarily performed using one of those three services, so it expects that data transfers over all other ports to be low. For the same reason, Cortex XDR Analytics also assumes endpoint traffic towards a specific destination should be about the same over long periods of time. An attacker may be exfiltrating data directly to the internet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. How to Reduce it /mitigation?&lt;/P&gt;
&lt;P&gt;You can created the Alert Exclusion or Automation rule for the same.&lt;BR /&gt;&amp;gt;&amp;gt; Alert Exclusion:&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Alert-Exclusions" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Alert-Exclusions&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt; Automation rule:&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Automation-Rules" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Automation-Rules&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. How to investigate it?&lt;/P&gt;
&lt;P&gt;Investigative actions:&lt;BR /&gt;&amp;gt;&amp;gt; Check if the traffic is related to SSH activity, it can trigger this alert. It is possible that someone on your network is legitimately engaged in SSH activity.&lt;BR /&gt;&amp;gt;&amp;gt; Check if the traffic is to/from a misconfigured network.&lt;BR /&gt;&amp;gt;&amp;gt; Check if the traffic is to a new external service or server that has recently been adopted for use by an organization in your enterprise.&lt;BR /&gt;&amp;gt;&amp;gt; Identify the process/user performing the data transfer to determine if the transfer is sanctioned.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please find the below helpful document for Cortex XDR Analytics Alert Reference:&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR-Analytics-Alert-Reference/Required-Data-Sources" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR-Analytics-Alert-Reference/Required-Data-Sources&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please find the below helpful document for Cortex XDR Analytics Alert Reference/Large-Upload-Generic:&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR-Analytics-Alert-Reference/Large-Upload-Generic" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR-Analytics-Alert-Reference/Large-Upload-Generic&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this will be helpful!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 13:53:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/large-upload-generic-microsoft-teams-alerts/m-p/569710#M5724</guid>
      <dc:creator>dbahuguna</dc:creator>
      <dc:date>2023-12-13T13:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: Large Upload(Generic) Microsoft Teams alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/large-upload-generic-microsoft-teams-alerts/m-p/569726#M5726</link>
      <description>&lt;P&gt;Thanks for your response!&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/221362"&gt;@dbahuguna&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;why most of the alerts are triggered from Microsoft Teams (&lt;SPAN&gt;ms-teams.exe)?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 15:46:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/large-upload-generic-microsoft-teams-alerts/m-p/569726#M5726</guid>
      <dc:creator>Vijisaga</dc:creator>
      <dc:date>2023-12-13T15:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Large Upload(Generic) Microsoft Teams alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/large-upload-generic-microsoft-teams-alerts/m-p/570259#M5756</link>
      <description>&lt;P&gt;I have the same problem. But in my case, I opened a case with the support team...&lt;BR /&gt;The answer was, every call with screen sharing, document sharing, etc... XDR will create an alert.&lt;/P&gt;
&lt;P&gt;The only chance of this not appear is accept the risk and create a pre process rule.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;DIV id="bodyDisplay_0" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 18 Dec 2023 18:20:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/large-upload-generic-microsoft-teams-alerts/m-p/570259#M5756</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2023-12-18T18:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: Large Upload(Generic) Microsoft Teams alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/large-upload-generic-microsoft-teams-alerts/m-p/570334#M5760</link>
      <description>&lt;P&gt;Thanks for the response&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;Some of the users confirmed that they haven't shared any data through ms-teams. so, in this case, what action needs to be performed?&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/221362"&gt;@dbahuguna&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 12:31:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/large-upload-generic-microsoft-teams-alerts/m-p/570334#M5760</guid>
      <dc:creator>Vijisaga</dc:creator>
      <dc:date>2023-12-19T12:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: Large Upload(Generic) Microsoft Teams alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/large-upload-generic-microsoft-teams-alerts/m-p/570372#M5764</link>
      <description>&lt;P&gt;in my case, when users start a meeting and sharing screen, the alert appear. but&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 17:19:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/large-upload-generic-microsoft-teams-alerts/m-p/570372#M5764</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2023-12-19T17:19:22Z</dc:date>
    </item>
    <item>
      <title>Re: Large Upload(Generic) Microsoft Teams alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/large-upload-generic-microsoft-teams-alerts/m-p/570374#M5766</link>
      <description>&lt;P&gt;confirm whether the destination IP is Microsoft Teams or not...&lt;BR /&gt;see this from the IP in the XDR Alert information and compare with the link "&lt;A href="https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide" target="_blank"&gt;Office 365 URLs and IP address ranges - Microsoft 365 Enterprise | Microsoft Learn&lt;/A&gt;"&lt;/P&gt;
&lt;P&gt;Then open a case with the support team....&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;DIV id="bodyDisplay_0" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;Hope this will be helpful!&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 19 Dec 2023 17:44:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/large-upload-generic-microsoft-teams-alerts/m-p/570374#M5766</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2023-12-19T17:44:26Z</dc:date>
    </item>
  </channel>
</rss>

