<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: wf_vericts json file verdict values? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wf-vericts-json-file-verdict-values/m-p/392204#M631</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/162770"&gt;@JoeDay&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It appears that you are trying to collect the local verdict for a file on an endpoint by extracting the wf_verdicts.db file. Currently, there's no public documentation available to share regarding the file. Would you like to explain that goal that you have in mind that would potentially utilize this information?&lt;/P&gt;</description>
    <pubDate>Thu, 18 Mar 2021 21:12:38 GMT</pubDate>
    <dc:creator>gjenkins</dc:creator>
    <dc:date>2021-03-18T21:12:38Z</dc:date>
    <item>
      <title>wf_vericts json file verdict values?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wf-vericts-json-file-verdict-values/m-p/391876#M624</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Exported&amp;nbsp;wf_verdicts.db from an endpoint to validate local verdicts. Is there any reference for return codes and their meanings?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;example:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;"value": {&lt;BR /&gt;"verdict": 3,&lt;BR /&gt;"lruData": {&lt;BR /&gt;"lastUsed": "1613061210",&lt;BR /&gt;"index": "65945"&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 22:33:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wf-vericts-json-file-verdict-values/m-p/391876#M624</guid>
      <dc:creator>JoeDay</dc:creator>
      <dc:date>2021-03-17T22:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: wf_vericts json file verdict values?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wf-vericts-json-file-verdict-values/m-p/392204#M631</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/162770"&gt;@JoeDay&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It appears that you are trying to collect the local verdict for a file on an endpoint by extracting the wf_verdicts.db file. Currently, there's no public documentation available to share regarding the file. Would you like to explain that goal that you have in mind that would potentially utilize this information?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 21:12:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wf-vericts-json-file-verdict-values/m-p/392204#M631</guid>
      <dc:creator>gjenkins</dc:creator>
      <dc:date>2021-03-18T21:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: wf_vericts json file verdict values?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wf-vericts-json-file-verdict-values/m-p/393951#M645</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd also like to point out that the local hash cache can be queried on Windows Endpoints using the following command which is more user-friendly than viewing the db file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;SPAN&gt;cytool wf query [&amp;lt;hash&amp;gt;]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: The supervisor password is required to issue this command.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-0/cortex-xdr-agent-admin/cortex-xdr-agent-for-windows/troubleshoot-cortex-xdr-for-windows/cytool.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-0/cortex-xdr-agent-admin/cortex-xdr-agent-for-windows/troubleshoot-cortex-xdr-for-windows/cytool.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 16:06:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wf-vericts-json-file-verdict-values/m-p/393951#M645</guid>
      <dc:creator>gjenkins</dc:creator>
      <dc:date>2021-03-25T16:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: wf_verdicts json file verdict values?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wf-vericts-json-file-verdict-values/m-p/397359#M658</link>
      <description>&lt;P&gt;The verdicts handling was changed in version 7.2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To check (verify) the verdict on the agent.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Export the entire wf_verdicts.db using cytool command: cytool persist export wf_verdicts.&lt;/LI&gt;&lt;LI&gt;Open the resulted JSON file using Text editor and search on the hash&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Verdicts:&lt;BR /&gt;Invalid = 0,&lt;BR /&gt;Benign = 1,&lt;BR /&gt;Malware = 2,&lt;BR /&gt;Unknown = 3,&lt;BR /&gt;Grayware = 4,&lt;BR /&gt;NoConnection = 5&lt;/P&gt;</description>
      <pubDate>Mon, 12 Apr 2021 21:01:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/wf-vericts-json-file-verdict-values/m-p/397359#M658</guid>
      <dc:creator>JoeDay</dc:creator>
      <dc:date>2021-04-12T21:01:48Z</dc:date>
    </item>
  </channel>
</rss>

