<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does Cortex XDR support encrypted macros? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-support-encrypted-macros/m-p/1219073#M7838</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203072"&gt;@DanRoberts&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank you for writing to LC!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Yes, I have seen such similar issues reported in the past.&lt;BR /&gt;&lt;BR /&gt;Symptom-&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;An MS Office application has been configured to prevent macro files in Excel from running when there is no Antivirus installed.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When a macro is tried to be executed on a machine that has no Antivirus installed, the message below will be seen.&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&lt;SPAN&gt;"This file contains encrypted macros that have been disabled because there is no antivirus software installed that can scan them. To run these macros, remove the encryption or permission restrictions on the file."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&amp;nbsp;However, Cortex XDR was installed and running properly with Malware Feature enabled.&lt;BR /&gt;&lt;BR /&gt;Cause and solution -&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It seems the feature checks if the macro file is password protected and an Anti-Virus can actually scan those files or not,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Cortex XDR does scan macro files in general but do not scan password protected files and this is its expected behavior or design.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;However, For some reason the Microsoft Feature does not accurately detect if an Antivirus software is installed and running.&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&lt;SPAN&gt;The feature may need to be consulted with the Microsoft Office Team since an Antivirus product is installed on the machine.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;Additionally,&amp;nbsp;Since Cortex XDR is working as expected. one work around would be to allow the said macro under&lt;A href="https://support.microsoft.com/en-us/office/add-remove-or-change-a-trusted-location-in-microsoft-office-7ee1cdc2-483e-4cbb-bcb3-4e7c67147fb4" target="_blank" rel="noopener"&gt; Trusted Location.&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Give it a like &amp;amp;&amp;nbsp;&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;&amp;nbsp;if this answer helped you.&lt;BR /&gt;&lt;BR /&gt;Best,&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Feb 2025 08:12:16 GMT</pubDate>
    <dc:creator>nar</dc:creator>
    <dc:date>2025-02-03T08:12:16Z</dc:date>
    <item>
      <title>Does Cortex XDR support encrypted macros?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-support-encrypted-macros/m-p/1218839#M7836</link>
      <description>&lt;P&gt;Getting this Office warning when trying to open a file containing an encrypted macro.&amp;nbsp; Are they supported?&amp;nbsp; If they are then why does the MS Windows Antivirus API incorrectly report?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanRoberts_0-1738314316381.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65636iD5EFD8922312F7F8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DanRoberts_0-1738314316381.png" alt="DanRoberts_0-1738314316381.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The host has Cortex XDR Agent 8.6.1 installed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 09:06:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-support-encrypted-macros/m-p/1218839#M7836</guid>
      <dc:creator>DanRoberts</dc:creator>
      <dc:date>2025-01-31T09:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cortex XDR support encrypted macros?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-support-encrypted-macros/m-p/1219073#M7838</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203072"&gt;@DanRoberts&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank you for writing to LC!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Yes, I have seen such similar issues reported in the past.&lt;BR /&gt;&lt;BR /&gt;Symptom-&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;An MS Office application has been configured to prevent macro files in Excel from running when there is no Antivirus installed.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When a macro is tried to be executed on a machine that has no Antivirus installed, the message below will be seen.&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&lt;SPAN&gt;"This file contains encrypted macros that have been disabled because there is no antivirus software installed that can scan them. To run these macros, remove the encryption or permission restrictions on the file."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&amp;nbsp;However, Cortex XDR was installed and running properly with Malware Feature enabled.&lt;BR /&gt;&lt;BR /&gt;Cause and solution -&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It seems the feature checks if the macro file is password protected and an Anti-Virus can actually scan those files or not,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Cortex XDR does scan macro files in general but do not scan password protected files and this is its expected behavior or design.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;However, For some reason the Microsoft Feature does not accurately detect if an Antivirus software is installed and running.&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&lt;SPAN&gt;The feature may need to be consulted with the Microsoft Office Team since an Antivirus product is installed on the machine.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;Additionally,&amp;nbsp;Since Cortex XDR is working as expected. one work around would be to allow the said macro under&lt;A href="https://support.microsoft.com/en-us/office/add-remove-or-change-a-trusted-location-in-microsoft-office-7ee1cdc2-483e-4cbb-bcb3-4e7c67147fb4" target="_blank" rel="noopener"&gt; Trusted Location.&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Give it a like &amp;amp;&amp;nbsp;&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;&amp;nbsp;if this answer helped you.&lt;BR /&gt;&lt;BR /&gt;Best,&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 08:12:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/does-cortex-xdr-support-encrypted-macros/m-p/1219073#M7838</guid>
      <dc:creator>nar</dc:creator>
      <dc:date>2025-02-03T08:12:16Z</dc:date>
    </item>
  </channel>
</rss>

