<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alert &amp;quot;Script Activity - 245655498&amp;quot; in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-quot-script-activity-245655498-quot/m-p/594458#M7052</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just received this alert "&lt;SPAN&gt;Script Activity - 245655498&lt;/SPAN&gt;" with this description "&lt;SPAN&gt;Suspicious script with keywords written in a non-standard way.&lt;/SPAN&gt;" in Cortex multiple times related to PowerShell script execution on a developer machine. The executed scripts were different and I don't know why Cortex is blocking such executions. There is also no documentation on this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alert source: XDR Agent&lt;/P&gt;
&lt;P&gt;Initiator and CGO path are the same in one of the alerts:&amp;nbsp;"C:\Program Files\PowerShell\7\pwsh.exe" -WindowStyle Minimized -file c:\folder1\script.ps1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Aug 2024 07:49:56 GMT</pubDate>
    <dc:creator>Arman_Zaheri</dc:creator>
    <dc:date>2024-08-09T07:49:56Z</dc:date>
    <item>
      <title>Alert "Script Activity - 245655498"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-quot-script-activity-245655498-quot/m-p/594458#M7052</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just received this alert "&lt;SPAN&gt;Script Activity - 245655498&lt;/SPAN&gt;" with this description "&lt;SPAN&gt;Suspicious script with keywords written in a non-standard way.&lt;/SPAN&gt;" in Cortex multiple times related to PowerShell script execution on a developer machine. The executed scripts were different and I don't know why Cortex is blocking such executions. There is also no documentation on this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alert source: XDR Agent&lt;/P&gt;
&lt;P&gt;Initiator and CGO path are the same in one of the alerts:&amp;nbsp;"C:\Program Files\PowerShell\7\pwsh.exe" -WindowStyle Minimized -file c:\folder1\script.ps1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 07:49:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-quot-script-activity-245655498-quot/m-p/594458#M7052</guid>
      <dc:creator>Arman_Zaheri</dc:creator>
      <dc:date>2024-08-09T07:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Alert "Script Activity - 245655498"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-quot-script-activity-245655498-quot/m-p/595244#M7087</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/922167235"&gt;@Arman_Zaheri&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on live community!&lt;/P&gt;
&lt;P&gt;This alert is due to the use of suspicious keywords/parameters in the script which may inline with malicious behaviour. Please investigate the causality chain and the involved command line. If script is benign and executed by your employees for legitimate purpose then you may need to create exception for it. To create exception, identify the module which triggered the alert from alert table. Then based on either script location or command line you can create exception for the module and apply to particular profile which was applied to developer machines.&lt;/P&gt;
&lt;P&gt;Please open a support case if you need more help with alert investigation/exception.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please c&lt;SPAN&gt;lick&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;to acknowledge that the answer to your question has been provided.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 16:13:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-quot-script-activity-245655498-quot/m-p/595244#M7087</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2024-08-19T16:13:50Z</dc:date>
    </item>
  </channel>
</rss>

