<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Masquerading - 4203898100 in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/masquerading-4203898100/m-p/583424#M6495</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;We had received a High incident while running a malware scan, it is&amp;nbsp;Masquerading - 4203898100, where the filezilla.exe application is detected as malicious and is blocked by the XDR. We observed that the endpoint is in disconnected state then also the similar incidents triggered with the same endpoint.&lt;/P&gt;
&lt;P&gt;My query is that why it is triggering multiple times, even though the file has been blocked and prevented by XDR, also when the device is in the disconnected state. We already received like 3 duplicate incidents.&lt;/P&gt;</description>
    <pubDate>Thu, 11 Apr 2024 19:12:23 GMT</pubDate>
    <dc:creator>AvinashAddala</dc:creator>
    <dc:date>2024-04-11T19:12:23Z</dc:date>
    <item>
      <title>Masquerading - 4203898100</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/masquerading-4203898100/m-p/583424#M6495</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;We had received a High incident while running a malware scan, it is&amp;nbsp;Masquerading - 4203898100, where the filezilla.exe application is detected as malicious and is blocked by the XDR. We observed that the endpoint is in disconnected state then also the similar incidents triggered with the same endpoint.&lt;/P&gt;
&lt;P&gt;My query is that why it is triggering multiple times, even though the file has been blocked and prevented by XDR, also when the device is in the disconnected state. We already received like 3 duplicate incidents.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 19:12:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/masquerading-4203898100/m-p/583424#M6495</guid>
      <dc:creator>AvinashAddala</dc:creator>
      <dc:date>2024-04-11T19:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: Masquerading - 4203898100</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/masquerading-4203898100/m-p/583924#M6520</link>
      <description>&lt;P&gt;&lt;SPAN class="il"&gt;Hi&amp;nbsp;AvinashAddala,&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Each related artifact, even if coming from different hosts, UEBA users or Cloud resources etc. will be used to pull more alerts and add them under the same incident story. The Incident/Alerts are grouped because they share a related artifact or attributes (alert source, type, file hash, or time period).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cortex uses ML for detection, incident grouping, and causality chaining of alerts that surface key artifacts such as users, IPs, and hosts and applies threat intelligence and malware sandboxing capabilities to understand assets that are impacted, and the context needed for an analyst to take appropriate action. Reference &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Incidents" target="_self"&gt;Incidents • Cortex XDR Prevent Administrator Guide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="il"&gt;If you feel these malware scan Masquerading findings are a false positive, please&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;generate a&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Retrieve-Support-Logs-from-an-Endpoint" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Retrieve-Support-Logs-from-an-Endpoint&amp;amp;source=gmail&amp;amp;ust=1713376820106000&amp;amp;usg=AOvVaw041wXyIx_8i0hVTBdhDwkg"&gt;TSF&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;file on an endpoint in question and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="il"&gt;open&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;a &lt;A title="support case" href="https://supportcases.paloaltonetworks.com/s/gethelp" target="_self"&gt;support&amp;nbsp;&lt;/A&gt;&lt;/SPAN&gt;&lt;A title="support case" href="https://supportcases.paloaltonetworks.com/s/gethelp" target="_self"&gt;&lt;SPAN class="il"&gt;case&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;A title="support case" href="https://supportcases.paloaltonetworks.com/s/gethelp" target="_self"&gt;&amp;nbsp;&lt;/A&gt;that an engineer can review.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;May I also suggest to bookmark the&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Agent-Releases/Cortex-XDR-Agent-Releases" target="_self" rel="nofollow noopener noreferrer"&gt;Cortex XDR Agent Releases&lt;/A&gt;&amp;nbsp;TechDoc which provides an overview of new features and known issues per agent release.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 18:34:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/masquerading-4203898100/m-p/583924#M6520</guid>
      <dc:creator>jtalton</dc:creator>
      <dc:date>2024-04-16T18:34:28Z</dc:date>
    </item>
  </channel>
</rss>

