<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR - Detected (Scanned) alert for malware in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-detected-scanned-alert-for-malware/m-p/401072#M683</link>
    <description>&lt;P&gt;Hello ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By default XDR don`t do anything malicious file ( if this file is not running). But you can quarantine this file ==&amp;gt; Endpoints/Policy Management/Profiles/Malware/&lt;SPAN&gt;Portable Executable and DLL Examination/QUARANTINE MALICIOUS EXECUTABLES&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Apr 2021 06:02:33 GMT</pubDate>
    <dc:creator>OrkanAlibayli</dc:creator>
    <dc:date>2021-04-22T06:02:33Z</dc:date>
    <item>
      <title>Cortex XDR - Detected (Scanned) alert for malware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-detected-scanned-alert-for-malware/m-p/401064#M682</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please excuse me if these are very basic questions. I have been trying to find a definitive, written answer and have been unable to, so far.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If&lt;/P&gt;
&lt;P&gt;1. Portable Executable and DLL Examination is set to the default of 'block' in an applied Cortex XDR policy,&lt;/P&gt;
&lt;P&gt;2. a scan is run on an endpoint using that policy&lt;/P&gt;
&lt;P&gt;and&lt;/P&gt;
&lt;P&gt;3. a malicious executable is found on that device, why does the alert show as "Detected (Scanned)" for the file?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is the endpoint protected from that malicious executable?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on the default setting, would that file be blocked if it attempted to execute and since it is dormant, it has only been identified during the scan but no action is necessary (other than an alert)?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for any help with this.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="description ng-star-inserted"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 22 Apr 2021 05:45:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-detected-scanned-alert-for-malware/m-p/401064#M682</guid>
      <dc:creator>Joe_Botelho</dc:creator>
      <dc:date>2021-04-22T05:45:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR - Detected (Scanned) alert for malware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-detected-scanned-alert-for-malware/m-p/401072#M683</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By default XDR don`t do anything malicious file ( if this file is not running). But you can quarantine this file ==&amp;gt; Endpoints/Policy Management/Profiles/Malware/&lt;SPAN&gt;Portable Executable and DLL Examination/QUARANTINE MALICIOUS EXECUTABLES&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 06:02:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-detected-scanned-alert-for-malware/m-p/401072#M683</guid>
      <dc:creator>OrkanAlibayli</dc:creator>
      <dc:date>2021-04-22T06:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR - Detected (Scanned) alert for malware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-detected-scanned-alert-for-malware/m-p/401462#M685</link>
      <description>&lt;P&gt;&lt;SPAN&gt;a malicious executable is found on that device, why does the alert show as "Detected (Scanned)" for the file?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Detected (Scanned) means we detected the file as malware during the scan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is the endpoint protected from that malicious executable? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes, because the default policy is in block mode&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Based on the default setting, would that file be blocked if it attempted to execute and since it is dormant, it has only been identified during the scan but no action is necessary (other than an alert)? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;yes it will be blocked, there is a setting to change quarantine malicious executable where you can change it to Quarantine Wildfire Malware verdict so that way file that is scanned and if it has WF malware verdict then it will be quarantined. Step 3 --&amp;gt; option 2 from the link below&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-profiles/add-malware-security-profile" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-profiles/add-malware-security-profile&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 07:18:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-detected-scanned-alert-for-malware/m-p/401462#M685</guid>
      <dc:creator>jcandelaria</dc:creator>
      <dc:date>2021-04-23T07:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR - Detected (Scanned) alert for malware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-detected-scanned-alert-for-malware/m-p/405065#M712</link>
      <description>&lt;P&gt;Thank you for the responses.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a follow up, if a file is on the blocklist already but is given a WildFire verdict and "Quarantine WildFire malware verdict" has been enabled in the applied malware profile, why isn't the file actually quarantined? Is it due to it already being on the blocklist?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2021 00:30:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-detected-scanned-alert-for-malware/m-p/405065#M712</guid>
      <dc:creator>Joe_Botelho</dc:creator>
      <dc:date>2021-05-06T00:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR - Detected (Scanned) alert for malware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-detected-scanned-alert-for-malware/m-p/405992#M728</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/171707"&gt;@Joe_Botelho&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The file should be moved to quarantine if the "&lt;SPAN&gt;Quarantine WildFire malware verdict" is flagged in the profile regardless of the fact it is in the block list.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In case it doesn't please do the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- validate the setting is enabled in the profile&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- validate the profile the agent is getting&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- open a support ticket to track the issue if none of the above works.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 09:46:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-detected-scanned-alert-for-malware/m-p/405992#M728</guid>
      <dc:creator>mabutbul</dc:creator>
      <dc:date>2021-05-11T09:46:24Z</dc:date>
    </item>
  </channel>
</rss>

