<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LSASS creating a cache1.bin on appdata in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/lsass-creating-a-cache1-bin-on-appdata/m-p/596061#M7116</link>
    <description>&lt;P&gt;Hello, we are also seeing this issue in our environment.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;The Cache0.bin\Cache1.bin file is generated within one or multiple service profiles in the folder&amp;nbsp;C:\Windows\ServiceProfiles\PROFILENAME\AppData\Local\Microsoft\Windows\SFAP\&lt;BR /&gt;&lt;BR /&gt;This cache file is always 0 bytes, and has a timestamp that corresponds with system event 5823 reporting that "The system successfully changed its password on the domain controller \\domain This event is logged when the password for the computer account is changed by the system. It is logged on the computer that changed the password."&lt;BR /&gt;&lt;BR /&gt;This has only affected a handful of systems, all within the past 7 days. Other systems have logged the 5823 events without triggering a Cortex/LSASS alert or creating the cache.bin file.&lt;BR /&gt;&lt;BR /&gt;Looking for any additional insight while determining root cause.&lt;/P&gt;</description>
    <pubDate>Tue, 27 Aug 2024 16:17:20 GMT</pubDate>
    <dc:creator>J.Eversvik</dc:creator>
    <dc:date>2024-08-27T16:17:20Z</dc:date>
    <item>
      <title>LSASS creating a cache1.bin on appdata</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/lsass-creating-a-cache1-bin-on-appdata/m-p/595872#M7107</link>
      <description>&lt;P&gt;We have an alert on 2 different device that&amp;nbsp;LSASS is creating a cache1.bin on app data.&lt;/P&gt;
&lt;P&gt;All are created by NT\SYSTEM&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Location detected&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;C:\Users&amp;lt;my username&amp;gt;\AppData\Local\Microsoft\Windows\SFAP\cache1.bin&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;C:\Windows\ServiceProfiles\UIFlowService\AppData\Local\Microsoft\Windows\SFAP\cache1.bin, C:\Windows\ServiceProfiles\pilogsrvX64\AppData\Local\Microsoft\Windows\SFAP\cache1.bin, C:\Windows\ServiceProfiles\pinetmgr\AppData\Local\Microsoft\Windows\SFAP\cache1.bin, C:\Windows\ServiceProfiles\pilogsrv\AppData\Local\Microsoft\Windows\SFAP\cache1.bin, C:\Windows\ServiceProfiles\pimsgss\AppData\Local\Microsoft\Windows\SFAP\cache1.bin\SFAP\cache1.bin&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried to search for same issue and found one on Microsoft but not answered.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/answers/questions/1336646/what-is-the-cache1-bin-on-windows-11" target="_blank"&gt;https://learn.microsoft.com/en-us/answers/questions/1336646/what-is-the-cache1-bin-on-windows-11&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have anyone experience this?&lt;/P&gt;
&lt;P&gt;What course of action taken?&lt;/P&gt;</description>
      <pubDate>Sun, 25 Aug 2024 23:28:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/lsass-creating-a-cache1-bin-on-appdata/m-p/595872#M7107</guid>
      <dc:creator>EricksonM</dc:creator>
      <dc:date>2024-08-25T23:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: LSASS creating a cache1.bin on appdata</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/lsass-creating-a-cache1-bin-on-appdata/m-p/595914#M7108</link>
      <description>&lt;P&gt;We have seen a few of these alerts ourselves but no idea why.&lt;/P&gt;
&lt;P&gt;As an additional piece of information, this event coincides with an event logged in the system log of affected hosts as per below:&lt;/P&gt;
&lt;P&gt;NETLOGON Event ID 5823&lt;BR /&gt;The system successfully changed its password on the domain controller \\Domaincontroller. This event is logged when the password for the computer account is changed by the system. It is logged on the computer that changed the password.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2024 08:58:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/lsass-creating-a-cache1-bin-on-appdata/m-p/595914#M7108</guid>
      <dc:creator>WGriessbach</dc:creator>
      <dc:date>2024-08-26T08:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: LSASS creating a cache1.bin on appdata</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/lsass-creating-a-cache1-bin-on-appdata/m-p/596026#M7113</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;After a quick analysis we can see that the path contains "&lt;SPAN&gt;SFAP" and the process LSASS loaded 2 DLL with this name. Both DLL are known and signed by Microsoft.&amp;nbsp;&lt;BR /&gt;I checked on other assets and I found 24 similar "cache1.bin" files created by LSASS on few assets. Seems legit.&lt;BR /&gt;&lt;BR /&gt;And this alert does not exist in Threat Vault to get more info.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 09:06:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/lsass-creating-a-cache1-bin-on-appdata/m-p/596026#M7113</guid>
      <dc:creator>ThomasDaCruz</dc:creator>
      <dc:date>2024-08-27T09:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: LSASS creating a cache1.bin on appdata</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/lsass-creating-a-cache1-bin-on-appdata/m-p/596061#M7116</link>
      <description>&lt;P&gt;Hello, we are also seeing this issue in our environment.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;The Cache0.bin\Cache1.bin file is generated within one or multiple service profiles in the folder&amp;nbsp;C:\Windows\ServiceProfiles\PROFILENAME\AppData\Local\Microsoft\Windows\SFAP\&lt;BR /&gt;&lt;BR /&gt;This cache file is always 0 bytes, and has a timestamp that corresponds with system event 5823 reporting that "The system successfully changed its password on the domain controller \\domain This event is logged when the password for the computer account is changed by the system. It is logged on the computer that changed the password."&lt;BR /&gt;&lt;BR /&gt;This has only affected a handful of systems, all within the past 7 days. Other systems have logged the 5823 events without triggering a Cortex/LSASS alert or creating the cache.bin file.&lt;BR /&gt;&lt;BR /&gt;Looking for any additional insight while determining root cause.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 16:17:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/lsass-creating-a-cache1-bin-on-appdata/m-p/596061#M7116</guid>
      <dc:creator>J.Eversvik</dc:creator>
      <dc:date>2024-08-27T16:17:20Z</dc:date>
    </item>
    <item>
      <title>Re: LSASS creating a cache1.bin on appdata</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/lsass-creating-a-cache1-bin-on-appdata/m-p/596209#M7121</link>
      <description>&lt;DIV dir="ltr"&gt;Issue seems to have been initiated by&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://support.microsoft.com/en-us/topic/august-13-2024-kb5041585-os-builds-22621-4037-and-22631-4037-76655cde-e2ee-49d4-a415-cf9a4d3c3a04" target="_blank" rel="noopener"&gt;KB5041585&lt;/A&gt;, which began deploying to the environment on 8/13/24. Microsoft is reporting that two vulnerabilities relating to the Local Security Authority Subsystem Service (LSASS) are addressed with this patch -&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38118" target="_blank" rel="noopener"&gt;CVE-2024-38118&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38122" target="_blank" rel="noopener"&gt;CVE-2024-38122&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Both of these are related to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A dir="ltr" href="https://cwe.mitre.org/data/definitions/908.html" target="_blank" rel="noopener"&gt;CWE-908: Use of Uninitialized Resource&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;
&lt;P&gt;Patch details note updates to these system files&lt;/P&gt;
&lt;P&gt;"SFAPM.dll","10.0.22621.3958","10-Aug-2024","20:35","293,360"&lt;BR /&gt;"SFAPE.dll","10.0.22621.3958","10-Aug-2024","20:35","51,720"&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;This patch has currently been deployed to hundreds systems, and I suspect that each will throw this alert when they renew their computer account password automatically.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have not found any signs of malicious activity related to these incidents, and do believe this is a new, but legitimate behavior from the Local Security Authority Subsystem Service.&lt;/DIV&gt;</description>
      <pubDate>Wed, 28 Aug 2024 14:44:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/lsass-creating-a-cache1-bin-on-appdata/m-p/596209#M7121</guid>
      <dc:creator>J.Eversvik</dc:creator>
      <dc:date>2024-08-28T14:44:55Z</dc:date>
    </item>
  </channel>
</rss>

