<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Suspicious Executable Detected in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspicious-executable-detected/m-p/581677#M6406</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/260826"&gt;@DerekC&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks for reaching out on LiveCommunity!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As per the internal updates,&amp;nbsp;the SOC analyzed the XDR alert and determined that this is a false positive.&amp;nbsp; There is no risk to your system and you can continue using it by clicking Ok in the pop up that you received.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Mar 2024 08:04:07 GMT</pubDate>
    <dc:creator>aspatil</dc:creator>
    <dc:date>2024-03-26T08:04:07Z</dc:date>
    <item>
      <title>Suspicious Executable Detected</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspicious-executable-detected/m-p/581537#M6399</link>
      <description>&lt;P&gt;We have had a number of users endpoints alert with the following:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DerekC_2-1711366036813.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58608i34AD4C6F6499F2D7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DerekC_2-1711366036813.png" alt="DerekC_2-1711366036813.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Subsequent scans of endpoints found nothing and there are not associated incidents within the portal.&lt;/P&gt;
&lt;P&gt;As can be seen, there is no identified application name or publisher. Is there any reason this would happen without incidents being recorded in the portal? Any ideas as to why we would see this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditorDerekC_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2024 11:31:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspicious-executable-detected/m-p/581537#M6399</guid>
      <dc:creator>DerekC</dc:creator>
      <dc:date>2024-03-25T11:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious Executable Detected</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspicious-executable-detected/m-p/581677#M6406</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/260826"&gt;@DerekC&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks for reaching out on LiveCommunity!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As per the internal updates,&amp;nbsp;the SOC analyzed the XDR alert and determined that this is a false positive.&amp;nbsp; There is no risk to your system and you can continue using it by clicking Ok in the pop up that you received.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 08:04:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspicious-executable-detected/m-p/581677#M6406</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-03-26T08:04:07Z</dc:date>
    </item>
  </channel>
</rss>

