<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Legacy Agent Exception in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception/m-p/578050#M6119</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a file and when I run it, Cortex XDR blocks it and shows me some information:&lt;BR /&gt;"""&lt;/P&gt;
&lt;P&gt;Application information:&lt;BR /&gt;Application name:  Windows Explorer&lt;BR /&gt;Application version:  10.0.22621.3007&lt;BR /&gt;Application publisher:  Microsoft Corporation&lt;BR /&gt;Process ID:  20676&lt;BR /&gt;Application location:  C:\Windows\explorer.exe&lt;BR /&gt;Command line:  C:\WINDOWS\Explorer.EXE&lt;BR /&gt;File origin:  Hard drive on this computer&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Target application information:&lt;BR /&gt;Application name:  Java(TM) Platform SE binary&lt;BR /&gt;Application version:  21.0.2.0&lt;BR /&gt;Application publisher:  Oracle Corporation&lt;BR /&gt;Process ID:  2432&lt;BR /&gt;Application location:  C:\Program Files\Java\jdk-21\bin\javaw.exe&lt;BR /&gt;Command line:  "C:\Program Files\Java\jdk-21\bin\javaw.exe" -jar "C:\Users\ayxanp\AppData\Local\Temp\961644af-8259-4735-a751-8b545a44ed02_apache-jmeter-5.6.3.tgz.d02\apache-jmeter-5.6.3\bin\ApacheJMeter.jar"&amp;nbsp;&lt;BR /&gt;File origin:  Hard drive on this computer&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Prevention information:&lt;BR /&gt;Prevention date:  Thursday, February 22, 2024&lt;BR /&gt;Prevention time:  11:30:43&lt;BR /&gt;OS version:  10.0.22631.2.0.0.256.1&lt;BR /&gt;Component:  Child Process Protection&lt;BR /&gt;Status code:  80400057&lt;BR /&gt;Prevention description:  Suspicious process creation detected&lt;BR /&gt;Additional information 1:  explorer.exe&lt;BR /&gt;Additional information 2:  C:\Program Files\Java\jdk-21\bin\javaw.exe&lt;BR /&gt;Additional information 3:  -jar "C:\Users\ayxanp\AppData\Local\Temp\961644af-8259-4735-a751-8b545a44ed02_apache-jmeter-5.6.3.tgz.d02\apache-jmeter-5.6.3\bin\ApacheJMeter.jar"&amp;nbsp;&lt;BR /&gt;Additional information 4:  ChildProcessPattern: *\javaw.exe, Flag: D, CommandLineRegex: ((?i)([-/]jar\s+\"?((\Q%temp%\E)|(\Q%templong%\E)|(\Q%SystemDrive%\E\\Users\\.*\\temp)|(\Q%SystemDrive%\E\\docume.*\\temp))\\.*))&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;"""&lt;BR /&gt;&lt;BR /&gt;I need to create legacy agent exception for that. When I go to this page, I choose "&lt;SPAN&gt;Malware &amp;gt; Malicious Child Process Protection" as module and it requires me to fill three things which are:&lt;BR /&gt;1.&amp;nbsp;Parent Process Name&lt;BR /&gt;2.&amp;nbsp;Child Process Name&lt;BR /&gt;3.&amp;nbsp;Child Process Command Line Params&lt;BR /&gt;&lt;BR /&gt;Can you tell me what should I write to these three fields according to my case? And, can you tell me whether I chose the module correct or not?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Feb 2024 11:07:27 GMT</pubDate>
    <dc:creator>JahidAliyev</dc:creator>
    <dc:date>2024-02-22T11:07:27Z</dc:date>
    <item>
      <title>Legacy Agent Exception</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception/m-p/578050#M6119</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a file and when I run it, Cortex XDR blocks it and shows me some information:&lt;BR /&gt;"""&lt;/P&gt;
&lt;P&gt;Application information:&lt;BR /&gt;Application name:  Windows Explorer&lt;BR /&gt;Application version:  10.0.22621.3007&lt;BR /&gt;Application publisher:  Microsoft Corporation&lt;BR /&gt;Process ID:  20676&lt;BR /&gt;Application location:  C:\Windows\explorer.exe&lt;BR /&gt;Command line:  C:\WINDOWS\Explorer.EXE&lt;BR /&gt;File origin:  Hard drive on this computer&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Target application information:&lt;BR /&gt;Application name:  Java(TM) Platform SE binary&lt;BR /&gt;Application version:  21.0.2.0&lt;BR /&gt;Application publisher:  Oracle Corporation&lt;BR /&gt;Process ID:  2432&lt;BR /&gt;Application location:  C:\Program Files\Java\jdk-21\bin\javaw.exe&lt;BR /&gt;Command line:  "C:\Program Files\Java\jdk-21\bin\javaw.exe" -jar "C:\Users\ayxanp\AppData\Local\Temp\961644af-8259-4735-a751-8b545a44ed02_apache-jmeter-5.6.3.tgz.d02\apache-jmeter-5.6.3\bin\ApacheJMeter.jar"&amp;nbsp;&lt;BR /&gt;File origin:  Hard drive on this computer&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Prevention information:&lt;BR /&gt;Prevention date:  Thursday, February 22, 2024&lt;BR /&gt;Prevention time:  11:30:43&lt;BR /&gt;OS version:  10.0.22631.2.0.0.256.1&lt;BR /&gt;Component:  Child Process Protection&lt;BR /&gt;Status code:  80400057&lt;BR /&gt;Prevention description:  Suspicious process creation detected&lt;BR /&gt;Additional information 1:  explorer.exe&lt;BR /&gt;Additional information 2:  C:\Program Files\Java\jdk-21\bin\javaw.exe&lt;BR /&gt;Additional information 3:  -jar "C:\Users\ayxanp\AppData\Local\Temp\961644af-8259-4735-a751-8b545a44ed02_apache-jmeter-5.6.3.tgz.d02\apache-jmeter-5.6.3\bin\ApacheJMeter.jar"&amp;nbsp;&lt;BR /&gt;Additional information 4:  ChildProcessPattern: *\javaw.exe, Flag: D, CommandLineRegex: ((?i)([-/]jar\s+\"?((\Q%temp%\E)|(\Q%templong%\E)|(\Q%SystemDrive%\E\\Users\\.*\\temp)|(\Q%SystemDrive%\E\\docume.*\\temp))\\.*))&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;"""&lt;BR /&gt;&lt;BR /&gt;I need to create legacy agent exception for that. When I go to this page, I choose "&lt;SPAN&gt;Malware &amp;gt; Malicious Child Process Protection" as module and it requires me to fill three things which are:&lt;BR /&gt;1.&amp;nbsp;Parent Process Name&lt;BR /&gt;2.&amp;nbsp;Child Process Name&lt;BR /&gt;3.&amp;nbsp;Child Process Command Line Params&lt;BR /&gt;&lt;BR /&gt;Can you tell me what should I write to these three fields according to my case? And, can you tell me whether I chose the module correct or not?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 11:07:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception/m-p/578050#M6119</guid>
      <dc:creator>JahidAliyev</dc:creator>
      <dc:date>2024-02-22T11:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy Agent Exception</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception/m-p/578179#M6131</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/274228"&gt;@JahidAliyev&lt;/a&gt;, thanks for reaching us using the Live Comminty.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looks like is a user starting a Java process that calls a jar file.&lt;/P&gt;
&lt;P&gt;Try with this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1.&amp;nbsp;Parent Process Name: explorer.exe&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2.&amp;nbsp;Child Process Name:&amp;nbsp;javaw.exe&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3.&amp;nbsp;Child Process Command Line Params:&amp;nbsp;-jar "C:\Users\ayxanp\AppData\Local\Temp\961644af-8259-4735-a751-8b545a44ed02_apache-jmeter-5.6.3.tgz.d02\apache-jmeter-5.6.3\bin\ApacheJMeter.jar"&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Let me know if that works.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 13:19:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception/m-p/578179#M6131</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-02-23T13:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy Agent Exception</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception/m-p/582623#M6458</link>
      <description>&lt;P&gt;I also face the same problem on multiple clients, but I didn't understand how your approach is different?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 11:44:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception/m-p/582623#M6458</guid>
      <dc:creator>Arman_Zaheri</dc:creator>
      <dc:date>2024-04-04T11:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy Agent Exception</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception/m-p/582629#M6459</link>
      <description>&lt;P&gt;I also tested something very interesting. I tried to run a JAR files directly (out of an archive like 7z, tgz and so on) and it executed without any problem. Then, in the second scenario, I put the JAR file into a 7z archive and tried to executed it from inside the archive and suddenly Cortex blocked it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, you can also extract your TGZ archive and try to run your JAR file.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 12:09:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/legacy-agent-exception/m-p/582629#M6459</guid>
      <dc:creator>Arman_Zaheri</dc:creator>
      <dc:date>2024-04-04T12:09:36Z</dc:date>
    </item>
  </channel>
</rss>

