<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BTD - PROCEXP152.SYS - Vulnerable Driver Loaded in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/btd-procexp152-sys-vulnerable-driver-loaded/m-p/1231743#M8436</link>
    <description>&lt;P&gt;&lt;STRONG&gt;Since Process Explorer can run without loading the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;procexp.sys&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;driver, does that mean we can safely block&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;procexp.sys&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;or&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;procexp152.sys&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;without affecting its core functionality? Or does Process Explorer lose important features without the driver?&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 14 Jun 2025 04:29:57 GMT</pubDate>
    <dc:creator>N.Patel578121</dc:creator>
    <dc:date>2025-06-14T04:29:57Z</dc:date>
    <item>
      <title>BTD - PROCEXP152.SYS - Vulnerable Driver Loaded</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/btd-procexp152-sys-vulnerable-driver-loaded/m-p/546485#M4599</link>
      <description>&lt;P&gt;Cortex blocked driver&amp;nbsp;&lt;SPAN&gt;PROCEXP152.SYS&lt;/SPAN&gt; from being loaded (rule: sync.vulnerable_driver_by_original_name_loaded_procexp)&lt;BR /&gt;The thing it that this is a signed microsoft driver and it's kind of a known situation for many other vendors.&lt;BR /&gt;&lt;BR /&gt;Links:&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/answers/questions/989267/process-explorer-procexp152-sys-driver-flagged-as" target="_blank"&gt;Process Explorer - ProcExp152.sys Driver Flagged As Vulnerable - Microsoft Q&amp;amp;A&lt;/A&gt;&amp;nbsp;,&amp;nbsp;&lt;A href="https://www.reddit.com/r/sysadmin/comments/10pw9b3/sentinelone_annoyance/" target="_self"&gt;SentinelOne annoyance! : r/sysadmin (reddit.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone seen this in Cortex before? What it's the best thing to do?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 13:07:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/btd-procexp152-sys-vulnerable-driver-loaded/m-p/546485#M4599</guid>
      <dc:creator>Panagiss</dc:creator>
      <dc:date>2023-06-20T13:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: BTD - PROCEXP152.SYS - Vulnerable Driver Loaded</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/btd-procexp152-sys-vulnerable-driver-loaded/m-p/546532#M4605</link>
      <description>&lt;P&gt;Hi Panagiss,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cortex XDR is indicating that this is a vulnerable driver, not that it is not a legitimate driver (we're not disputing that it's signed by MS).&amp;nbsp; A common tactic used by attackers is to take advantage of highly trusted binaries which are vulnerable to abuse to perform actions like killing EDR tools.&amp;nbsp; There are many examples of executables which are vulnerable to misuse, including older versions of the process explorer binary.&amp;nbsp; To prevent misuse, Cortex XDR blocks loading of vulnerable versions of this executable by default.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to allow this driver to be loaded in your environment, you can create a&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-a-Disable-Prevention-Rule" target="_self"&gt;Disable Prevention Rule&lt;/A&gt;&amp;nbsp;and (optionally) an&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-an-Alert-Exclusion-Rule" target="_self"&gt;Alert Exclusion&lt;/A&gt;&amp;nbsp;to allow the driver to be loaded and suppress associated alerts from the console.&amp;nbsp; Keep in mind that this will create a risk for your organization as attackers could exploit this driver to kill Cortex XDR on the endpoint they have gained access to.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 15:37:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/btd-procexp152-sys-vulnerable-driver-loaded/m-p/546532#M4605</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2023-06-20T15:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: BTD - PROCEXP152.SYS - Vulnerable Driver Loaded</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/btd-procexp152-sys-vulnerable-driver-loaded/m-p/1219788#M7851</link>
      <description>&lt;P&gt;Hi Afurze,&lt;/P&gt;
&lt;P&gt;thanks a lot for this topic, i'm starting to work with Cortex XDR, and i found this topic, and just for my information(in a learning mode in my lab), i wan't to test creating an Disable prevention rule, to allow driver&amp;nbsp;&lt;SPAN&gt;procexp152.sys to be load, but i didn't find where or how to create it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Contacting support they sent me a Support Exception Rules, but what i want is to understand how to create it manually for future investigation and not import a rule received from support.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks a lot if you can help me.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2025 11:09:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/btd-procexp152-sys-vulnerable-driver-loaded/m-p/1219788#M7851</guid>
      <dc:creator>Davide_Mattei</dc:creator>
      <dc:date>2025-02-07T11:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: BTD - PROCEXP152.SYS - Vulnerable Driver Loaded</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/btd-procexp152-sys-vulnerable-driver-loaded/m-p/1231743#M8436</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Since Process Explorer can run without loading the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;procexp.sys&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;driver, does that mean we can safely block&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;procexp.sys&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;or&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;procexp152.sys&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;without affecting its core functionality? Or does Process Explorer lose important features without the driver?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Jun 2025 04:29:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/btd-procexp152-sys-vulnerable-driver-loaded/m-p/1231743#M8436</guid>
      <dc:creator>N.Patel578121</dc:creator>
      <dc:date>2025-06-14T04:29:57Z</dc:date>
    </item>
  </channel>
</rss>

