<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SynRpcServer.exe in System32 folder in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/synrpcserver-exe-in-system32-folder/m-p/995927#M7518</link>
    <description>&lt;P&gt;It was from: XDR Analytics BIOC&lt;/P&gt;</description>
    <pubDate>Mon, 02 Dec 2024 08:55:29 GMT</pubDate>
    <dc:creator>Panagiss</dc:creator>
    <dc:date>2024-12-02T08:55:29Z</dc:date>
    <item>
      <title>SynRpcServer.exe in System32 folder</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/synrpcserver-exe-in-system32-folder/m-p/847149#M7493</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I got an alert "Globally rare process execution from a signed process" and after investigating the process is &lt;SPAN class="cell-value-text ng-star-inserted" title="C:\Windows\System32\SynRpcServer.exe"&gt;SynRpcServer.exe&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="copy-to-clip-box ng-star-inserted" title="Copy to clipboard"&gt;which not uncommon and also the host uses a fingerprint sensor so it should all make sense. &lt;BR /&gt;&lt;BR /&gt;But the interesting parts are on the causality chain are:&lt;BR /&gt;&lt;BR /&gt;
&lt;DIV class="description-wrapper"&gt;
&lt;DIV class="text"&gt;
&lt;DIV class="items-list ng-star-inserted"&gt;
&lt;UL&gt;
&lt;LI class="desc-item ng-star-inserted"&gt;&lt;SPAN class="desc-text"&gt;SynRpcServer.exe executed "SynRpcServer.exe".&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class="desc-item ng-star-inserted"&gt;&lt;SPAN class="desc-text"&gt;T&lt;/SPAN&gt;&lt;SPAN class="desc-text"&gt;he acting process is signed by Synaptics Incorporated.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class="desc-item ng-star-inserted"&gt;&lt;SPAN class="desc-text"&gt;This signed vendor, image name and executed process combination is globally uncommon.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
Furthermore the location of the exe is in System32 folder:&lt;BR /&gt;&lt;EM&gt;C:\Windows\System32\SynRpcServer.exe&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;Hash (of the parent&amp;nbsp;&lt;SPAN class="desc-text"&gt;SynRpcServer.exe)&lt;/SPAN&gt; 10a416072f3e581e2943f07453c5484e503c47131e48674245564030de2dd531&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Any thoughts on this?&lt;/DIV&gt;</description>
      <pubDate>Wed, 27 Nov 2024 15:31:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/synrpcserver-exe-in-system32-folder/m-p/847149#M7493</guid>
      <dc:creator>Panagiss</dc:creator>
      <dc:date>2024-11-27T15:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: SynRpcServer.exe in System32 folder</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/synrpcserver-exe-in-system32-folder/m-p/995655#M7506</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/286023"&gt;@Panagiss&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What module is generating the alert? BTP? Analytics?&lt;/P&gt;
&lt;P&gt;Maybe the fingerprint driver/app has been updated and it is behaving different as before.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2024 20:13:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/synrpcserver-exe-in-system32-folder/m-p/995655#M7506</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-11-28T20:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: SynRpcServer.exe in System32 folder</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/synrpcserver-exe-in-system32-folder/m-p/995927#M7518</link>
      <description>&lt;P&gt;It was from: XDR Analytics BIOC&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 08:55:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/synrpcserver-exe-in-system32-folder/m-p/995927#M7518</guid>
      <dc:creator>Panagiss</dc:creator>
      <dc:date>2024-12-02T08:55:29Z</dc:date>
    </item>
  </channel>
</rss>

