<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XDR - portproxy enabled allow a man-in-the-middle attack in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-portproxy-enabled-allow-a-man-in-the-middle-attack/m-p/585073#M6604</link>
    <description>&lt;P&gt;Hi&lt;BR /&gt;&lt;BR /&gt;Does anyone know if &lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;detect and/or protect against this type of attack:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.syxsense.com/syxsense-securityarticles/disa_stig_benchmarks/syx-1036-13731.html?agt=index" target="_blank"&gt;Windows 10 must not have portproxy enabled or in use (syxsense.com)&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Apr 2024 14:59:25 GMT</pubDate>
    <dc:creator>tlmarques</dc:creator>
    <dc:date>2024-04-26T14:59:25Z</dc:date>
    <item>
      <title>XDR - portproxy enabled allow a man-in-the-middle attack</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-portproxy-enabled-allow-a-man-in-the-middle-attack/m-p/585073#M6604</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;&lt;BR /&gt;Does anyone know if &lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;detect and/or protect against this type of attack:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.syxsense.com/syxsense-securityarticles/disa_stig_benchmarks/syx-1036-13731.html?agt=index" target="_blank"&gt;Windows 10 must not have portproxy enabled or in use (syxsense.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 14:59:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-portproxy-enabled-allow-a-man-in-the-middle-attack/m-p/585073#M6604</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-04-26T14:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: XDR - portproxy enabled allow a man-in-the-middle attack</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-portproxy-enabled-allow-a-man-in-the-middle-attack/m-p/585095#M6607</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did a test in my lab by modifying the registry as mentioned in the link, and it was not detected by the XDR Agent as malicious.&lt;/P&gt;
&lt;P&gt;In this cases you can create custom BIOCs to detect this behaviors that might not be malicious by themselves.&lt;/P&gt;
&lt;P&gt;I have created this custom BIOC rule that you can apply in &lt;STRONG&gt;Detection Rules - BIOC - Add Bioc&lt;/STRONG&gt; to detect modifications to this registry key.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;dataset = xdr_data 
| filter event_type = ENUM.REGISTRY and event_sub_type = ENUM.REGISTRY_CREATE_KEY 
| filter action_registry_key_name contains  """HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\PortProxy\\"""&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;Tested and working as expected:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1714161955058.png" style="width: 325px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59322i381E006FCD4A0E9F/image-dimensions/325x519/is-moderation-mode/true?v=v2" width="325" height="519" role="button" title="jmazzeo_0-1714161955058.png" alt="jmazzeo_0-1714161955058.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;You can even add the BIOC to a Restriction Profile and block the process doing the registry modification.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 20:07:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-portproxy-enabled-allow-a-man-in-the-middle-attack/m-p/585095#M6607</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-04-26T20:07:18Z</dc:date>
    </item>
  </channel>
</rss>

