<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Interpreting alerts on XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/interpreting-alerts-on-xdr/m-p/1219836#M7857</link>
    <description>&lt;P&gt;From the alert info you provided. It seems the dll is detected scanned means it was either found during periodic scan or user initiated scan. since it is a dll it wont be quarantined. It is detected by the Local analysis module so if you want to allow this dll when it is actually loaded into a process then you can either add its hash to allow list or add a legacy agent exception on pe and dll examination module and then selecting either the signer of the dll or the dll path. You can also add a disable prevention rule so that you get the alert but the dll is still allowed to run on the endpoint.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Also since it is scanned the alert will have many empty fields. When You run the relevant application and this dll is loaded then it would provide all details such as causality graph, the signers and api calls performed and so on on the causality view. &amp;nbsp; Hope I covered few things that could help.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 08 Feb 2025 14:59:16 GMT</pubDate>
    <dc:creator>Fm12345</dc:creator>
    <dc:date>2025-02-08T14:59:16Z</dc:date>
    <item>
      <title>Interpreting alerts on XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/interpreting-alerts-on-xdr/m-p/1219609#M7847</link>
      <description>&lt;P&gt;Hi, The alerts on XDR and very much rigid and not readable even to the support personnel, whenever I raise a case they keep checking with other teams teams and higher support levels to get details, for example how to interpret the below, it says suspicious DLL detected, however many of these DLL's are part of known applications and are intact, how to identify the reason XDR is saying suspicious.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;27/01/2025 09:01:04.000 XABCN N/A Medium No XDR Agent Detected (Scanned) Malware Local Analysis Malware Suspicious DLL detected N/A N/A N/A D:\FNFC Data\Desktop\P1\Example.dll No No DS:PANW/XDR Agent, EG:-&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 07:28:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/interpreting-alerts-on-xdr/m-p/1219609#M7847</guid>
      <dc:creator>M.Almosawi</dc:creator>
      <dc:date>2025-02-06T07:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: Interpreting alerts on XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/interpreting-alerts-on-xdr/m-p/1219836#M7857</link>
      <description>&lt;P&gt;From the alert info you provided. It seems the dll is detected scanned means it was either found during periodic scan or user initiated scan. since it is a dll it wont be quarantined. It is detected by the Local analysis module so if you want to allow this dll when it is actually loaded into a process then you can either add its hash to allow list or add a legacy agent exception on pe and dll examination module and then selecting either the signer of the dll or the dll path. You can also add a disable prevention rule so that you get the alert but the dll is still allowed to run on the endpoint.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Also since it is scanned the alert will have many empty fields. When You run the relevant application and this dll is loaded then it would provide all details such as causality graph, the signers and api calls performed and so on on the causality view. &amp;nbsp; Hope I covered few things that could help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Feb 2025 14:59:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/interpreting-alerts-on-xdr/m-p/1219836#M7857</guid>
      <dc:creator>Fm12345</dc:creator>
      <dc:date>2025-02-08T14:59:16Z</dc:date>
    </item>
  </channel>
</rss>

