<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR missing powershell logging in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-missing-powershell-logging/m-p/578924#M6222</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/170886"&gt;@Vadim_Lisserman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This has more to do with what was your action process vs what was the actor process, in the case where PowerShell is doing the click action/ acting it is called the actor process , and when PowerShell is being spawned by another process that calls PowerShell it is called the action process, and hence, the detection is dependent on the action process in this case, while not all detection have he same criteria but this is in your use case.&lt;BR /&gt;&lt;BR /&gt;You can create custom detection as well, by utilizing the correlation rule, and in order for you to find the inspected script executed by PowerShell, you can utilize the AMSI scan buffer, that sits between the scripting engine, in our case PowerShell, and the XDR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zarnous_0-1709245598288.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57985i8EF679A248B3CF7E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="zarnous_0-1709245598288.png" alt="zarnous_0-1709245598288.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I have also went over this and how to look at the AMSI scan buffer content&amp;nbsp; in a different post that you may check here -&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xqls-for-powershell-script-logging/td-p/542059" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xqls-for-powershell-script-logging/td-p/542059&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Hope that was helpful, and if it answers your question please feel free to mark this as a solution so others can benefit from.&lt;BR /&gt;&lt;BR /&gt;Thanks&amp;nbsp;&lt;BR /&gt;Z&lt;/P&gt;</description>
    <pubDate>Thu, 29 Feb 2024 22:28:21 GMT</pubDate>
    <dc:creator>zarnous</dc:creator>
    <dc:date>2024-02-29T22:28:21Z</dc:date>
    <item>
      <title>Cortex XDR missing powershell logging</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-missing-powershell-logging/m-p/577275#M6065</link>
      <description>&lt;P&gt;I'm doing some Powershell detection testing and I noticed that when I open the Powershell GUI in windows and run a command below it doesn't trigger a Powershell detection.&amp;nbsp; However, when I add powershell in front of the command it does trigger an event. I'm pretty sure this always wasn't the case.&amp;nbsp; Curios to see if this is expected behavior or something is broken with XDR.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Start-BitsTransfer -Priority foreground -Source &lt;A href="https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1197/T1197.md" target="_blank"&gt;https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1197/T1197.md&lt;/A&gt; -Destination c:\source\flag.ps1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 21:22:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-missing-powershell-logging/m-p/577275#M6065</guid>
      <dc:creator>Vadim_Lisserman</dc:creator>
      <dc:date>2024-02-14T21:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR missing powershell logging</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-missing-powershell-logging/m-p/577288#M6066</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/170886"&gt;@Vadim_Lisserman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have XDR pro license, and if you have it, its enable in the agents?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 01:47:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-missing-powershell-logging/m-p/577288#M6066</guid>
      <dc:creator>Alejandro_Hernandez</dc:creator>
      <dc:date>2024-02-15T01:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR missing powershell logging</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-missing-powershell-logging/m-p/577337#M6071</link>
      <description>&lt;P&gt;Yes, and yes.&amp;nbsp; Have you tried this in your environment are you seeing different results?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 13:48:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-missing-powershell-logging/m-p/577337#M6071</guid>
      <dc:creator>Vadim_Lisserman</dc:creator>
      <dc:date>2024-02-15T13:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR missing powershell logging</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-missing-powershell-logging/m-p/578924#M6222</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/170886"&gt;@Vadim_Lisserman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This has more to do with what was your action process vs what was the actor process, in the case where PowerShell is doing the click action/ acting it is called the actor process , and when PowerShell is being spawned by another process that calls PowerShell it is called the action process, and hence, the detection is dependent on the action process in this case, while not all detection have he same criteria but this is in your use case.&lt;BR /&gt;&lt;BR /&gt;You can create custom detection as well, by utilizing the correlation rule, and in order for you to find the inspected script executed by PowerShell, you can utilize the AMSI scan buffer, that sits between the scripting engine, in our case PowerShell, and the XDR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zarnous_0-1709245598288.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57985i8EF679A248B3CF7E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="zarnous_0-1709245598288.png" alt="zarnous_0-1709245598288.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I have also went over this and how to look at the AMSI scan buffer content&amp;nbsp; in a different post that you may check here -&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xqls-for-powershell-script-logging/td-p/542059" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xqls-for-powershell-script-logging/td-p/542059&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Hope that was helpful, and if it answers your question please feel free to mark this as a solution so others can benefit from.&lt;BR /&gt;&lt;BR /&gt;Thanks&amp;nbsp;&lt;BR /&gt;Z&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 22:28:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-missing-powershell-logging/m-p/578924#M6222</guid>
      <dc:creator>zarnous</dc:creator>
      <dc:date>2024-02-29T22:28:21Z</dc:date>
    </item>
  </channel>
</rss>

