<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: An endpoint with the Cortex XDR installation intermittently creates a huge file and writes to the hard drive at C:\Windows\System32\PaloNull in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/an-endpoint-with-the-cortex-xdr-installation-intermittently/m-p/599816#M7290</link>
    <description>&lt;P&gt;Good day A file with the same name and size is created on the administrator's desktop for all available disk space.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Oct 2024 20:05:40 GMT</pubDate>
    <dc:creator>Salenko</dc:creator>
    <dc:date>2024-10-08T20:05:40Z</dc:date>
    <item>
      <title>An endpoint with the Cortex XDR installation intermittently creates a huge file and writes to the hard drive at C:\Windows\System32\PaloNull</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/an-endpoint-with-the-cortex-xdr-installation-intermittently/m-p/511318#M2502</link>
      <description>&lt;P&gt;Dear Live Community Members,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One of my customers noticed that some endpoints with the Cortex XDR installation sometimes creates a huge file that grows in size with time.&lt;/P&gt;
&lt;P&gt;On several VMs equipped with the Cortex Agent (version 7.7.1, but we also noticed this with older versions in the past) sometimes a file called "PaloNull" is created, which grows really huge and eventually uses up all free disk space on the C: drive.&lt;/P&gt;
&lt;P&gt;We cannot leave the file in place when this occurs since it impedes normal operation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This data are being written/saved to the hard drive at the C Drive at the below location:&lt;BR /&gt;&lt;STRONG&gt;C:\Windows\System32\PaloNull&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PalNull.png" style="width: 741px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43056i11A151A41C59AB4E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PalNull.png" alt="PalNull.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This happened on approx. 10-15 VMs running Windows Server 2016 up to 2022 (maybe even older versions) within the last 12 months. &lt;BR /&gt;An older VM (Windows Server 2016) had Cortex installed for almost two years, whereas the newest VM (Windows Server 2022) was equipped with Cortex just a month ago.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The customer correlates this to Cortex due to the name (PaloNull) and&amp;nbsp;the fact that this occurred also on systems with no other PAN software installed (we ruled out PAN TS Agent for NGFW User ID as a cause just before creating this ticket).&lt;BR /&gt;Apart from the default Windows Defender which we leave untouched, no other security software is installed on the affected devices.&lt;/P&gt;
&lt;P&gt;I could not find any info about similar issues and the sample file does not provide any useful data.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a sample of that file, but I can't access and read the data from it:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PaloNull_1.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43057i283D14698E3AB59F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PaloNull_1.PNG" alt="PaloNull_1.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Could you help me out and let me know if this is a known bug? And how can we troubleshoot why this happens?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm struggling to confirm that this file has been in fact created by the Cortex XDR and the reason behind it.&lt;/P&gt;
&lt;P&gt;And I will really appreciate your help and any hints to investigate this issue further.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 15:27:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/an-endpoint-with-the-cortex-xdr-installation-intermittently/m-p/511318#M2502</guid>
      <dc:creator>A_Adamski</dc:creator>
      <dc:date>2022-08-09T15:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: An endpoint with the Cortex XDR installation intermittently creates a huge file and writes to the hard drive at C:\Windows\System32\PaloNull</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/an-endpoint-with-the-cortex-xdr-installation-intermittently/m-p/511319#M2503</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One or more tools that are installed on the system may be causing this issue. Please raise a support ticket with our Customer Support team to help investigate and fix this issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Silviu&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 15:34:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/an-endpoint-with-the-cortex-xdr-installation-intermittently/m-p/511319#M2503</guid>
      <dc:creator>SilviuMihailDascalu</dc:creator>
      <dc:date>2022-08-09T15:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: An endpoint with the Cortex XDR installation intermittently creates a huge file and writes to the hard drive at C:\Windows\System32\PaloNull</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/an-endpoint-with-the-cortex-xdr-installation-intermittently/m-p/511350#M2504</link>
      <description>&lt;P&gt;Please let us know, how this Problem could be solved.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 20:05:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/an-endpoint-with-the-cortex-xdr-installation-intermittently/m-p/511350#M2504</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-08-09T20:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: An endpoint with the Cortex XDR installation intermittently creates a huge file and writes to the hard drive at C:\Windows\System32\PaloNull</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/an-endpoint-with-the-cortex-xdr-installation-intermittently/m-p/517625#M3006</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Dear All,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The engineering team saw 1 or 2 similar things in the past a long time ago. In all the cases it has been related to 3rd software (like nirsoft utility or some other system-wide tools).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So far, the issue did not occur again. We did include a check in our monitoring system, and as soon as it reappears, we will investigate further and reopen the case with the PA TAC.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 14:44:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/an-endpoint-with-the-cortex-xdr-installation-intermittently/m-p/517625#M3006</guid>
      <dc:creator>A_Adamski</dc:creator>
      <dc:date>2022-10-12T14:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: An endpoint with the Cortex XDR installation intermittently creates a huge file and writes to the hard drive at C:\Windows\System32\PaloNull</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/an-endpoint-with-the-cortex-xdr-installation-intermittently/m-p/599816#M7290</link>
      <description>&lt;P&gt;Good day A file with the same name and size is created on the administrator's desktop for all available disk space.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 20:05:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/an-endpoint-with-the-cortex-xdr-installation-intermittently/m-p/599816#M7290</guid>
      <dc:creator>Salenko</dc:creator>
      <dc:date>2024-10-08T20:05:40Z</dc:date>
    </item>
  </channel>
</rss>

