<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex false positives for OneDriveLauncher.exe? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-false-positives-for-onedrivelauncher-exe/m-p/1230934#M8376</link>
    <description>&lt;P&gt;We've been seeing the same for the last couple of weeks. Either associated directly with OneDrive or occasionally with Word and an ai.exe process (assuming co-pilot here). Good to know we're not alone and that it will be fixed in the next content pack. Any ideas on dates for that please?&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 08:41:52 GMT</pubDate>
    <dc:creator>Karl-Foley</dc:creator>
    <dc:date>2025-06-04T08:41:52Z</dc:date>
    <item>
      <title>Cortex false positives for OneDriveLauncher.exe?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-false-positives-for-onedrivelauncher-exe/m-p/1230876#M8369</link>
      <description>&lt;P&gt;For the last few days I've had random machines (some with fresh Windows installs) triggering Cortex alerts when logging into OneDrive.&lt;/P&gt;
&lt;P&gt;The alert is&amp;nbsp;&lt;EM&gt;Behavioral threat detected (rule: parent_process_spoofing) &lt;/EM&gt;and the path is the legitimate OneDrive executable at&amp;nbsp;&lt;EM&gt;C:\Program Files\Microsoft OneDrive\25.085.0504.0002\OneDriveLauncher.exe&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone else been seeing this?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 12:35:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-false-positives-for-onedrivelauncher-exe/m-p/1230876#M8369</guid>
      <dc:creator>JGrover1</dc:creator>
      <dc:date>2025-06-03T12:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex false positives for OneDriveLauncher.exe?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-false-positives-for-onedrivelauncher-exe/m-p/1230888#M8370</link>
      <description>&lt;P&gt;I have also been seeing this, exact same path and version of OneDrive.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 14:54:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-false-positives-for-onedrivelauncher-exe/m-p/1230888#M8370</guid>
      <dc:creator>austin.griffin</dc:creator>
      <dc:date>2025-06-03T14:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex false positives for OneDriveLauncher.exe?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-false-positives-for-onedrivelauncher-exe/m-p/1230895#M8373</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out LC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This false positive has already been noticed and is planned to be fixed on next content releases.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please test out after next release and if issue still persists open a support ticket to get further analysis on your issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this answered your question please mark as solution.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 17:11:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-false-positives-for-onedrivelauncher-exe/m-p/1230895#M8373</guid>
      <dc:creator>mavega</dc:creator>
      <dc:date>2025-06-03T17:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex false positives for OneDriveLauncher.exe?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-false-positives-for-onedrivelauncher-exe/m-p/1230901#M8374</link>
      <description>&lt;P&gt;I've seen process spoofing incidents on&amp;nbsp;&lt;SPAN&gt;FileCoAuth.exe,&amp;nbsp;OneDriveLauncher.exe, and&amp;nbsp;OneDrive.exe.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 19:38:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-false-positives-for-onedrivelauncher-exe/m-p/1230901#M8374</guid>
      <dc:creator>D.Moore415468</dc:creator>
      <dc:date>2025-06-03T19:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex false positives for OneDriveLauncher.exe?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-false-positives-for-onedrivelauncher-exe/m-p/1230902#M8375</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are also receiving the same alert, but it's from a different file path. Can you please confirm that this is a false positive? I would like to know why Cortex XDR is blocking it, as it is a legitimate file:&lt;/P&gt;
&lt;P&gt;C:\Users\xxx\AppData\Local\Microsoft\OneDrive\25.085.0504.0002\OneDriveLauncher.exe&lt;/P&gt;
&lt;P&gt;C:\Users\xxx\AppData\Local\Microsoft\OneDrive\25.085.0504.0002\FileCoAuth.exe&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 19:39:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-false-positives-for-onedrivelauncher-exe/m-p/1230902#M8375</guid>
      <dc:creator>Vijisaga</dc:creator>
      <dc:date>2025-06-03T19:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex false positives for OneDriveLauncher.exe?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-false-positives-for-onedrivelauncher-exe/m-p/1230934#M8376</link>
      <description>&lt;P&gt;We've been seeing the same for the last couple of weeks. Either associated directly with OneDrive or occasionally with Word and an ai.exe process (assuming co-pilot here). Good to know we're not alone and that it will be fixed in the next content pack. Any ideas on dates for that please?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 08:41:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-false-positives-for-onedrivelauncher-exe/m-p/1230934#M8376</guid>
      <dc:creator>Karl-Foley</dc:creator>
      <dc:date>2025-06-04T08:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex false positives for OneDriveLauncher.exe?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-false-positives-for-onedrivelauncher-exe/m-p/1231395#M8394</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Thanks for the clarification. Just to confirm, after which content release should we expect this problem is fixed? We're still receiving this alert, and I need to compare the client content version with the fixed one.&lt;/P&gt;
&lt;P&gt;Br,&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jun 2025 08:04:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-false-positives-for-onedrivelauncher-exe/m-p/1231395#M8394</guid>
      <dc:creator>Arman_Zaheri</dc:creator>
      <dc:date>2025-06-10T08:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex false positives for OneDriveLauncher.exe?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-false-positives-for-onedrivelauncher-exe/m-p/1231708#M8426</link>
      <description>&lt;P&gt;We haven't seen this issue after the content update released on 10th June:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-and-Traps-Content-Update-Release-Notes-Version-1820/Version-Information" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-and-Traps-Content-Update-Release-Notes-Version-1820/Version-Information&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Although I have noticed the release notes have changed as it originally showed this:&lt;/P&gt;
&lt;DIV id="tinyMceEditor_6173962786006fKarlFoley_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="This was in the original 10th June content release notes" style="width: 932px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68030i20537088670E840E/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="This was in the original 10th June content release notes" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;This was in the original 10th June content release notes&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jun 2025 08:14:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-false-positives-for-onedrivelauncher-exe/m-p/1231708#M8426</guid>
      <dc:creator>Karl-Foley</dc:creator>
      <dc:date>2025-06-13T08:14:03Z</dc:date>
    </item>
  </channel>
</rss>

