<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False Positive Issue - Multiple Windows System Processes Flagged by Cortex XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/false-positive-issue-multiple-windows-system-processes-flagged/m-p/1235619#M8635</link>
    <description>&lt;P&gt;Hi Yonghui_Yang,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there can be several reasons why you get triggered those alerts.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe legit executables changed name or location ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe legit execs trying to perform suspicious activity even though they were executed from original legit folder and names, but our analytics detect it as something suspicious.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2 things can be done if none of the former.&lt;/P&gt;
&lt;OL class="lia-list-style-type-upper-alpha"&gt;
&lt;LI&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI&gt;Alert Tunning so you prevent many false positive flooding. I can recommend 2 webinars even though they are a bit aged:
&lt;OL&gt;
&lt;LI&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-videos/cortex-xdr-customer-success-webinar-series-part-1-alert-tuning/ta-p/584842/redirect_from_archived_page/true" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-videos/cortex-xdr-customer-success-webinar-series-part-1-alert-tuning/ta-p/584842/redirect_from_archived_page/true&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-videos/cortex-xdr-customer-success-webinar-series-part-2-alert-tuning/ta-p/588312" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-videos/cortex-xdr-customer-success-webinar-series-part-2-alert-tuning/ta-p/588312&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Automated actions as response to alerts, also called simple automation rules:&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/cortex-xdr-how-to-video-simple-automation-rules/ta-p/568454" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/cortex-xdr-how-to-video-simple-automation-rules/ta-p/568454&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Open a TAC support case if none of the former works&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR,&lt;/P&gt;
&lt;P&gt;Luis&lt;/P&gt;</description>
    <pubDate>Thu, 07 Aug 2025 15:34:55 GMT</pubDate>
    <dc:creator>eluis</dc:creator>
    <dc:date>2025-08-07T15:34:55Z</dc:date>
    <item>
      <title>False Positive Issue - Multiple Windows System Processes Flagged by Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/false-positive-issue-multiple-windows-system-processes-flagged/m-p/1235586#M8632</link>
      <description>&lt;P class="whitespace-normal break-words"&gt;Hello everyone,&lt;/P&gt;
&lt;P class="whitespace-normal break-words"&gt;I'm experiencing ongoing false positive alerts with Cortex XDR that are affecting multiple endpoints in our environment. I'm seeking guidance on how to properly address this issue.&lt;/P&gt;
&lt;P class="whitespace-normal break-words"&gt;&lt;STRONG&gt;Environment Information:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL class="[&amp;amp;:not(:last-child)_ul]:pb-1 [&amp;amp;:not(:last-child)_ol]:pb-1 list-disc space-y-1.5 pl-7"&gt;
&lt;LI class="whitespace-normal break-words"&gt;Cortex XDR Agent Version: 8.6.0.3704&lt;/LI&gt;
&lt;LI class="whitespace-normal break-words"&gt;Operating System: Windows 10 64-bit&lt;/LI&gt;
&lt;LI class="whitespace-normal break-words"&gt;Issue Scope: All endpoints in the environment&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="whitespace-normal break-words"&gt;&lt;STRONG&gt;Problem Description:&lt;/STRONG&gt; We're getting consistent false positive alerts for the following legitimate Windows system processes across all our Windows 10 machines:&lt;/P&gt;
&lt;UL class="[&amp;amp;:not(:last-child)_ul]:pb-1 [&amp;amp;:not(:last-child)_ol]:pb-1 list-disc space-y-1.5 pl-7"&gt;
&lt;LI class="whitespace-normal break-words"&gt;Sihost.exe (Shell Infrastructure Host)&lt;/LI&gt;
&lt;LI class="whitespace-normal break-words"&gt;PhoneExperienceHost.exe&lt;/LI&gt;
&lt;LI class="whitespace-normal break-words"&gt;RuntimeBroker.exe&lt;/LI&gt;
&lt;LI class="whitespace-normal break-words"&gt;StartMenuExperienceHost.exe&lt;/LI&gt;
&lt;LI class="whitespace-normal break-words"&gt;backgroundTaskHost.exe&lt;/LI&gt;
&lt;LI class="whitespace-normal break-words"&gt;SearchApp.exe&lt;/LI&gt;
&lt;LI class="whitespace-normal break-words"&gt;BackgroundTransferHost.exe&lt;/LI&gt;
&lt;LI class="whitespace-normal break-words"&gt;TextInputHost.exe&lt;/LI&gt;
&lt;LI class="whitespace-normal break-words"&gt;HxTsr.exe&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="whitespace-normal break-words"&gt;These alerts are occurring continuously and affecting our entire fleet of endpoints.&lt;/P&gt;
&lt;P class="whitespace-normal break-words"&gt;&lt;STRONG&gt;Questions:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL class="[&amp;amp;:not(:last-child)_ul]:pb-1 [&amp;amp;:not(:last-child)_ol]:pb-1 list-decimal space-y-1.5 pl-7"&gt;
&lt;LI class="whitespace-normal break-words"&gt;Is this a known issue with Agent Version 8.6.0.3704 on Windows 10?&lt;/LI&gt;
&lt;LI class="whitespace-normal break-words"&gt;What's the recommended approach to create exceptions for these legitimate Windows processes?&lt;/LI&gt;
&lt;LI class="whitespace-normal break-words"&gt;Are there any planned updates to address these false positives?&lt;/LI&gt;
&lt;LI class="whitespace-normal break-words"&gt;Should I report this through official support channels as well?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="whitespace-normal break-words"&gt;Any guidance or similar experiences shared would be greatly appreciated. These false positives are creating alert fatigue and potentially masking real threats.&lt;/P&gt;
&lt;P class="whitespace-normal break-words"&gt;Thank you for your assistance.&lt;/P&gt;
&lt;P class="whitespace-normal break-words"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-08-07_150647.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68791i2E420643C0441903/image-size/large?v=v2&amp;amp;px=999" role="button" title="2025-08-07_150647.jpg" alt="2025-08-07_150647.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-08-07_150548.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68790iE133899E409CED8B/image-size/large?v=v2&amp;amp;px=999" role="button" title="2025-08-07_150548.jpg" alt="2025-08-07_150548.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-08-07_150235.jpg" style="width: 947px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68789i61A6B7C85ADFFC88/image-size/large?v=v2&amp;amp;px=999" role="button" title="2025-08-07_150235.jpg" alt="2025-08-07_150235.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Aug 2025 07:43:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/false-positive-issue-multiple-windows-system-processes-flagged/m-p/1235586#M8632</guid>
      <dc:creator>Yonghui_Yang</dc:creator>
      <dc:date>2025-08-07T07:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive Issue - Multiple Windows System Processes Flagged by Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/false-positive-issue-multiple-windows-system-processes-flagged/m-p/1235619#M8635</link>
      <description>&lt;P&gt;Hi Yonghui_Yang,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there can be several reasons why you get triggered those alerts.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe legit executables changed name or location ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe legit execs trying to perform suspicious activity even though they were executed from original legit folder and names, but our analytics detect it as something suspicious.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2 things can be done if none of the former.&lt;/P&gt;
&lt;OL class="lia-list-style-type-upper-alpha"&gt;
&lt;LI&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI&gt;Alert Tunning so you prevent many false positive flooding. I can recommend 2 webinars even though they are a bit aged:
&lt;OL&gt;
&lt;LI&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-videos/cortex-xdr-customer-success-webinar-series-part-1-alert-tuning/ta-p/584842/redirect_from_archived_page/true" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-videos/cortex-xdr-customer-success-webinar-series-part-1-alert-tuning/ta-p/584842/redirect_from_archived_page/true&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-videos/cortex-xdr-customer-success-webinar-series-part-2-alert-tuning/ta-p/588312" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-videos/cortex-xdr-customer-success-webinar-series-part-2-alert-tuning/ta-p/588312&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Automated actions as response to alerts, also called simple automation rules:&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/cortex-xdr-how-to-video-simple-automation-rules/ta-p/568454" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/cortex-xdr-how-to-video-simple-automation-rules/ta-p/568454&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Open a TAC support case if none of the former works&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR,&lt;/P&gt;
&lt;P&gt;Luis&lt;/P&gt;</description>
      <pubDate>Thu, 07 Aug 2025 15:34:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/false-positive-issue-multiple-windows-system-processes-flagged/m-p/1235619#M8635</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2025-08-07T15:34:55Z</dc:date>
    </item>
  </channel>
</rss>

