<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Behavioral threat detected (rule: bioc.sync.critical_termination) Triggered By Known Good Files in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-detected-rule-bioc-sync-critical-termination/m-p/594247#M7046</link>
    <description>&lt;P&gt;Hi, I've added an alert exception for the detected file (&lt;SPAN&gt;PhotosService.exe)&amp;nbsp;&lt;/SPAN&gt;but&amp;nbsp;&lt;SPAN&gt;Behavioral threat detected (rule: bioc.sync.critical_termination) is still being triggered when I try to launch the Photos app.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Aug 2024 14:58:49 GMT</pubDate>
    <dc:creator>jdbst56</dc:creator>
    <dc:date>2024-08-07T14:58:49Z</dc:date>
    <item>
      <title>Behavioral threat detected (rule: bioc.sync.critical_termination) Triggered By Known Good Files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-detected-rule-bioc-sync-critical-termination/m-p/594174#M7039</link>
      <description>&lt;P&gt;Over the past two weeks we have been seeing detections/blocks from the following rule "&lt;SPAN&gt;Behavioral threat detected (rule: bioc.sync.critical_termination)" for known good files&amp;nbsp;7z2301-x64.exe (7-zip install) and PhotosService.exe (part of built-in Windows Photos app).&amp;nbsp; We only see the detections on a few systems, many systems have these same files without any detections.&amp;nbsp; VirusTotal shows both files as clean and WildFire indicates they are benign.&amp;nbsp; What is causing these detections to keep recurring for Behavioral threat detected (rule: bioc.sync.critical_termination) for these files only on certain systems?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We have a case open since early last week but have not made any progress on this issue so I thought I would post here.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 17:26:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-detected-rule-bioc-sync-critical-termination/m-p/594174#M7039</guid>
      <dc:creator>jdbst56</dc:creator>
      <dc:date>2024-08-06T17:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: Behavioral threat detected (rule: bioc.sync.critical_termination) Triggered By Known Good Files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-detected-rule-bioc-sync-critical-termination/m-p/594211#M7043</link>
      <description>&lt;P&gt;While the case is analyzed and If it's a false positive then you can right click on the alert and add alert exception.. select the files based on which you want to add exception.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This would make sure that alert is not triggered again on those files by that specific rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can later review your exception based on the case feedback&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 07:03:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-detected-rule-bioc-sync-critical-termination/m-p/594211#M7043</guid>
      <dc:creator>Fm12345</dc:creator>
      <dc:date>2024-08-07T07:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Behavioral threat detected (rule: bioc.sync.critical_termination) Triggered By Known Good Files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-detected-rule-bioc-sync-critical-termination/m-p/594247#M7046</link>
      <description>&lt;P&gt;Hi, I've added an alert exception for the detected file (&lt;SPAN&gt;PhotosService.exe)&amp;nbsp;&lt;/SPAN&gt;but&amp;nbsp;&lt;SPAN&gt;Behavioral threat detected (rule: bioc.sync.critical_termination) is still being triggered when I try to launch the Photos app.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 14:58:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-detected-rule-bioc-sync-critical-termination/m-p/594247#M7046</guid>
      <dc:creator>jdbst56</dc:creator>
      <dc:date>2024-08-07T14:58:49Z</dc:date>
    </item>
    <item>
      <title>Re: Behavioral threat detected (rule: bioc.sync.critical_termination) Triggered By Known Good Files</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-detected-rule-bioc-sync-critical-termination/m-p/648878#M7459</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A id="link_20" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/300716" target="_self" aria-label="View Profile of jdbst56"&gt;&lt;SPAN class=""&gt;jdbst56&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You can right click on the alert and go to: manage alert option-&amp;gt; exclude alert.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The agent continues to raise excluded alerts on the endpoint, but they are not saved or displayed in Cortex XDR.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;More information about exclusion:&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Alert-Exclusions" target="_blank" rel="noopener"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Alert-Exclusions&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 08:16:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/behavioral-threat-detected-rule-bioc-sync-critical-termination/m-p/648878#M7459</guid>
      <dc:creator>E.Jafarov</dc:creator>
      <dc:date>2024-11-22T08:16:39Z</dc:date>
    </item>
  </channel>
</rss>

