<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Suspecting XDR Agent Blocking Sysprep Process Randomly in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspecting-xdr-agent-blocking-sysprep-process-randomly/m-p/1235285#M8619</link>
    <description>&lt;P&gt;Palo TAC&amp;nbsp; Support Feedback was to go with File Protection disable under Agent Security Settings. Test with updated version would help to remove unnecessary profiles.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Aug 2025 06:01:58 GMT</pubDate>
    <dc:creator>kpatel35ntt</dc:creator>
    <dc:date>2025-08-04T06:01:58Z</dc:date>
    <item>
      <title>Suspecting XDR Agent Blocking Sysprep Process Randomly</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspecting-xdr-agent-blocking-sysprep-process-randomly/m-p/1235190#M8612</link>
      <description>&lt;P&gt;We have noticed random block of sysprep process and ending up corrupting image. Has anyone noticed this?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Aug 2025 07:28:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspecting-xdr-agent-blocking-sysprep-process-randomly/m-p/1235190#M8612</guid>
      <dc:creator>kpatel35ntt</dc:creator>
      <dc:date>2025-08-01T07:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: Suspecting XDR Agent Blocking Sysprep Process Randomly</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspecting-xdr-agent-blocking-sysprep-process-randomly/m-p/1235222#M8614</link>
      <description>&lt;P&gt;Hi Kpatel35ntt,&lt;/P&gt;
&lt;P&gt;It seems to me that this random block of sysprep has to do with our detection thinking that a legit process is maybe used in a suspicious way.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see this have to be investigated further, so I would recommed to open a TAC support case, to figure out the root cause of false positives on sysprep behavior&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A temporal solution would be to create a legacy exception on that process/path/hash... the more you narrow down, the better&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR,&lt;/P&gt;
&lt;P&gt;Luis&lt;/P&gt;</description>
      <pubDate>Fri, 01 Aug 2025 15:13:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspecting-xdr-agent-blocking-sysprep-process-randomly/m-p/1235222#M8614</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2025-08-01T15:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: Suspecting XDR Agent Blocking Sysprep Process Randomly</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspecting-xdr-agent-blocking-sysprep-process-randomly/m-p/1235275#M8618</link>
      <description>&lt;P&gt;Check this knowledge base article:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000blZlKAI" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000blZlKAI&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Could be the issue you have.&lt;/P&gt;
&lt;P&gt;Hope this helps&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2025 05:20:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspecting-xdr-agent-blocking-sysprep-process-randomly/m-p/1235275#M8618</guid>
      <dc:creator>micomi</dc:creator>
      <dc:date>2025-08-04T05:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: Suspecting XDR Agent Blocking Sysprep Process Randomly</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspecting-xdr-agent-blocking-sysprep-process-randomly/m-p/1235285#M8619</link>
      <description>&lt;P&gt;Palo TAC&amp;nbsp; Support Feedback was to go with File Protection disable under Agent Security Settings. Test with updated version would help to remove unnecessary profiles.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2025 06:01:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspecting-xdr-agent-blocking-sysprep-process-randomly/m-p/1235285#M8619</guid>
      <dc:creator>kpatel35ntt</dc:creator>
      <dc:date>2025-08-04T06:01:58Z</dc:date>
    </item>
  </channel>
</rss>

