<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Repeated False Incidents with Unknown Verdicts in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/repeated-false-incidents-with-unknown-verdicts/m-p/1232311#M8468</link>
    <description>&lt;P data-start="186" data-end="198"&gt;Hi everyone,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P data-start="200" data-end="330"&gt;I’m currently facing an issue with Cortex XDR where I regularly receive incidents flagged as suspicious,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="384" data-end="410"&gt;This particular one shows:&lt;/P&gt;
&lt;UL data-start="411" data-end="490"&gt;
&lt;LI data-start="411" data-end="449"&gt;
&lt;P data-start="413" data-end="449"&gt;&lt;STRONG data-start="413" data-end="438"&gt;WF (WildFire) Verdict&lt;/STRONG&gt;: &lt;CODE data-start="440" data-end="449"&gt;Unknown&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="450" data-end="490"&gt;
&lt;P data-start="452" data-end="490"&gt;&lt;STRONG data-start="452" data-end="471"&gt;VT (VirusTotal)&lt;/STRONG&gt;: &lt;CODE data-start="473" data-end="479"&gt;0/64&lt;/CODE&gt; detections&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="492" data-end="844"&gt;Every week, I keep seeing similar incidents, often related to legitimate services or vendors (e.g., Tata CLiQ Luxury in this case), with no solid indication of malicious behavior. Since WildFire gives an "Unknown" verdict, I can't report it for reanalysis. And as the detection rate in VirusTotal is 0/64, there’s no strong indication of threat either.&lt;/P&gt;
&lt;P data-start="846" data-end="862"&gt;&lt;STRONG data-start="846" data-end="862"&gt;My concerns:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL data-start="863" data-end="1226"&gt;
&lt;LI data-start="863" data-end="958"&gt;
&lt;P data-start="866" data-end="958"&gt;Is there a better way to handle these rather than manually creating exceptions for each one?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="959" data-end="1041"&gt;
&lt;P data-start="962" data-end="1041"&gt;Can we automate the trust for such low-risk alerts based on certain conditions?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1042" data-end="1155"&gt;
&lt;P data-start="1045" data-end="1155"&gt;Are there any best practices that can help in reducing noise from such recurring false positives?&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Mon, 23 Jun 2025 05:32:30 GMT</pubDate>
    <dc:creator>V.R800240</dc:creator>
    <dc:date>2025-06-23T05:32:30Z</dc:date>
    <item>
      <title>Repeated False Incidents with Unknown Verdicts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/repeated-false-incidents-with-unknown-verdicts/m-p/1232311#M8468</link>
      <description>&lt;P data-start="186" data-end="198"&gt;Hi everyone,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P data-start="200" data-end="330"&gt;I’m currently facing an issue with Cortex XDR where I regularly receive incidents flagged as suspicious,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="384" data-end="410"&gt;This particular one shows:&lt;/P&gt;
&lt;UL data-start="411" data-end="490"&gt;
&lt;LI data-start="411" data-end="449"&gt;
&lt;P data-start="413" data-end="449"&gt;&lt;STRONG data-start="413" data-end="438"&gt;WF (WildFire) Verdict&lt;/STRONG&gt;: &lt;CODE data-start="440" data-end="449"&gt;Unknown&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="450" data-end="490"&gt;
&lt;P data-start="452" data-end="490"&gt;&lt;STRONG data-start="452" data-end="471"&gt;VT (VirusTotal)&lt;/STRONG&gt;: &lt;CODE data-start="473" data-end="479"&gt;0/64&lt;/CODE&gt; detections&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="492" data-end="844"&gt;Every week, I keep seeing similar incidents, often related to legitimate services or vendors (e.g., Tata CLiQ Luxury in this case), with no solid indication of malicious behavior. Since WildFire gives an "Unknown" verdict, I can't report it for reanalysis. And as the detection rate in VirusTotal is 0/64, there’s no strong indication of threat either.&lt;/P&gt;
&lt;P data-start="846" data-end="862"&gt;&lt;STRONG data-start="846" data-end="862"&gt;My concerns:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL data-start="863" data-end="1226"&gt;
&lt;LI data-start="863" data-end="958"&gt;
&lt;P data-start="866" data-end="958"&gt;Is there a better way to handle these rather than manually creating exceptions for each one?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="959" data-end="1041"&gt;
&lt;P data-start="962" data-end="1041"&gt;Can we automate the trust for such low-risk alerts based on certain conditions?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1042" data-end="1155"&gt;
&lt;P data-start="1045" data-end="1155"&gt;Are there any best practices that can help in reducing noise from such recurring false positives?&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 23 Jun 2025 05:32:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/repeated-false-incidents-with-unknown-verdicts/m-p/1232311#M8468</guid>
      <dc:creator>V.R800240</dc:creator>
      <dc:date>2025-06-23T05:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: Repeated False Incidents with Unknown Verdicts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/repeated-false-incidents-with-unknown-verdicts/m-p/1232347#M8472</link>
      <description>&lt;P&gt;Hi&amp;nbsp;V.R800240,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There has to be a reason why SF did not answer with a verdict.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe there was a problem when trying to load the sample into sandbox, or sandbox could not execute the file....&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Further investigations should be make so please feel free to open a TAC support case.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the meantime you can add the hash to allow list to prevent the incidents to be opened, after TAC gives you a final solution, remember to clean your allow list from temporary hashes.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="bodyDisplay_1" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;Feel free to click on like the answer if this helped you.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luis&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-rating-metoo lia-component-me-too-solution lia-component-message-view-widget-me-too-solution"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 23 Jun 2025 13:47:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/repeated-false-incidents-with-unknown-verdicts/m-p/1232347#M8472</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2025-06-23T13:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: Repeated False Incidents with Unknown Verdicts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/repeated-false-incidents-with-unknown-verdicts/m-p/1232443#M8477</link>
      <description>&lt;P&gt;Ok. Thanks for the update. I'll create a TAC case.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 03:54:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/repeated-false-incidents-with-unknown-verdicts/m-p/1232443#M8477</guid>
      <dc:creator>V.R800240</dc:creator>
      <dc:date>2025-06-24T03:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: Repeated False Incidents with Unknown Verdicts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/repeated-false-incidents-with-unknown-verdicts/m-p/1232478#M8479</link>
      <description>&lt;P&gt;Hi again,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I could not find on our labs a case in which we have unknown verdict.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you go to unknown verdict could you tweak it as grayware ? and then wait for a response from our analysts ?&lt;/P&gt;
&lt;P&gt;That might work too if you have the possibility while TAC is working on this&lt;/P&gt;
&lt;DIV id="bodyDisplay_1" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;Feel free to click on like the answer if this helped you.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luis&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-rating-metoo lia-component-me-too-solution lia-component-message-view-widget-me-too-solution"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 24 Jun 2025 13:13:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/repeated-false-incidents-with-unknown-verdicts/m-p/1232478#M8479</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2025-06-24T13:13:02Z</dc:date>
    </item>
  </channel>
</rss>

