<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Vuln drivers - scan in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/vuln-drivers-scan/m-p/649409#M7462</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone know if is possible to retrieve the devices with drivers with vulnerabilities?&lt;BR /&gt;I've a lot devices with &lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;and my objective is force IT guys, update vulnerable drivers etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Nov 2024 12:30:02 GMT</pubDate>
    <dc:creator>tlmarques</dc:creator>
    <dc:date>2024-11-22T12:30:02Z</dc:date>
    <item>
      <title>Vuln drivers - scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/vuln-drivers-scan/m-p/649409#M7462</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone know if is possible to retrieve the devices with drivers with vulnerabilities?&lt;BR /&gt;I've a lot devices with &lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;and my objective is force IT guys, update vulnerable drivers etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 12:30:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/vuln-drivers-scan/m-p/649409#M7462</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-11-22T12:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: Vuln drivers - scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/vuln-drivers-scan/m-p/684582#M7478</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for your query on LC!&lt;BR /&gt;&lt;BR /&gt;XDR offers built in rules which basically detects and reports vulnerable drivers so one way I could think of is building an XQL to filter the hosts that have these "Vulnerable driver loaded" alerts and we can also run a query to list all the unsigned drivers to investigate on.&lt;BR /&gt;&lt;BR /&gt;Give a like or mark as solution if this suggestion helped.&lt;BR /&gt;&lt;BR /&gt;Best,&lt;BR /&gt;Naveen&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 07:38:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/vuln-drivers-scan/m-p/684582#M7478</guid>
      <dc:creator>nar</dc:creator>
      <dc:date>2024-11-26T07:38:53Z</dc:date>
    </item>
    <item>
      <title>Re: Vuln drivers - scan</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/vuln-drivers-scan/m-p/704415#M7482</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/196805"&gt;@nar&lt;/a&gt;&amp;nbsp; thnks, i know that, my problem is, it dont see the filter in XQL for "description"&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tlmarques_0-1732647357602.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/64287i8161A70A15157599/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="tlmarques_0-1732647357602.png" alt="tlmarques_0-1732647357602.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 18:56:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/vuln-drivers-scan/m-p/704415#M7482</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-11-26T18:56:32Z</dc:date>
    </item>
  </channel>
</rss>

