<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Inconsistent AnyDesk Detection in Cortex XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/inconsistent-anydesk-detection-in-cortex-xdr/m-p/1250641#M9205</link>
    <description>&lt;P&gt;Hi everyone,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I'm observing inconsistent detection behavior in Cortex XDR during weekly on-demand scans related to the AnyDesk application.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;On some endpoints, AnyDesk is detected as "Suspicious executable detected", while on others no alert is generated, even though the application is present.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;One common pattern we observed is that the alerts are triggered when AnyDesk is executed from the following path:&lt;BR /&gt;C:\Users\user123\Downloads\AnyDesk.exe&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Additionally, the file hash appears to be the same across both detected and non-detected endpoints.&lt;BR /&gt;&lt;BR /&gt;Why is this detection triggered on some machines while not triggered on others?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 21 Mar 2026 21:48:43 GMT</pubDate>
    <dc:creator>M.Erkenci</dc:creator>
    <dc:date>2026-03-21T21:48:43Z</dc:date>
    <item>
      <title>Inconsistent AnyDesk Detection in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/inconsistent-anydesk-detection-in-cortex-xdr/m-p/1250641#M9205</link>
      <description>&lt;P&gt;Hi everyone,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I'm observing inconsistent detection behavior in Cortex XDR during weekly on-demand scans related to the AnyDesk application.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;On some endpoints, AnyDesk is detected as "Suspicious executable detected", while on others no alert is generated, even though the application is present.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;One common pattern we observed is that the alerts are triggered when AnyDesk is executed from the following path:&lt;BR /&gt;C:\Users\user123\Downloads\AnyDesk.exe&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Additionally, the file hash appears to be the same across both detected and non-detected endpoints.&lt;BR /&gt;&lt;BR /&gt;Why is this detection triggered on some machines while not triggered on others?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Mar 2026 21:48:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/inconsistent-anydesk-detection-in-cortex-xdr/m-p/1250641#M9205</guid>
      <dc:creator>M.Erkenci</dc:creator>
      <dc:date>2026-03-21T21:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent AnyDesk Detection in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/inconsistent-anydesk-detection-in-cortex-xdr/m-p/1250726#M9210</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1035790587"&gt;@M.Erkenci&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="269" data-start="0"&gt;Inconsistent detection behavior for the &lt;STRONG data-end="51" data-start="40"&gt;AnyDesk&lt;/STRONG&gt; application during on-demand or periodic scans—especially when the file hash is identical across endpoints—is usually caused by differences in policy, verdict handling, or alert visibility rather than the file itself.&lt;/P&gt;
&lt;H4 data-end="322" data-start="276" data-section-id="oo0id0"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 data-end="322" data-start="276" data-section-id="oo0id0"&gt;Potential Causes for Inconsistent Detection&lt;/H4&gt;
&lt;H4 data-end="381" data-start="324" data-section-id="qoq4im"&gt;1. Malware Security Profile Settings (Local Analysis)&lt;/H4&gt;
&lt;P data-end="530" data-start="382"&gt;If the WildFire verdict for the AnyDesk hash is &lt;STRONG data-end="443" data-start="430"&gt;“Unknown”&lt;/STRONG&gt; or &lt;STRONG data-end="476" data-start="447"&gt;“Benign – Low Confidence”&lt;/STRONG&gt;, the Cortex XDR agent may rely on &lt;STRONG data-end="529" data-start="511"&gt;Local Analysis&lt;/STRONG&gt;.&lt;/P&gt;
&lt;UL data-end="738" data-start="532"&gt;
&lt;LI data-end="674" data-start="532" data-section-id="15gubvs"&gt;If &lt;STRONG data-end="561" data-start="537"&gt;“Run Local Analysis”&lt;/STRONG&gt; is enabled, endpoints can evaluate the file differently based on:
&lt;UL data-end="674" data-start="630"&gt;
&lt;LI data-end="650" data-start="630" data-section-id="1in3ud8"&gt;Local engine state&lt;/LI&gt;
&lt;LI data-end="674" data-start="653" data-section-id="1ekagr9"&gt;Cached intelligence&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI data-end="738" data-start="675" data-section-id="tje7wk"&gt;Result: One machine flags it as suspicious, another does not.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="787" data-start="745" data-section-id="1c2elr8"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 data-end="787" data-start="745" data-section-id="1c2elr8"&gt;2. “Treat Grayware as Malware” Setting&lt;/H4&gt;
&lt;P data-end="873" data-start="788"&gt;AnyDesk is often classified as &lt;STRONG data-end="872" data-start="819"&gt;grayware / PUA (Potentially Unwanted Application)&lt;/STRONG&gt;.&lt;/P&gt;
&lt;UL data-end="1008" data-start="875"&gt;
&lt;LI data-end="1008" data-start="875" data-section-id="w43ku3"&gt;If &lt;STRONG data-end="911" data-start="880"&gt;“Treat Grayware as Malware”&lt;/STRONG&gt; is:
&lt;UL data-end="1008" data-start="918"&gt;
&lt;LI data-end="980" data-start="918" data-section-id="1ncfe8h"&gt;&lt;STRONG data-end="931" data-start="920"&gt;Enabled&lt;/STRONG&gt; → alerts like &lt;EM data-end="980" data-start="946"&gt;“Suspicious executable detected”&lt;/EM&gt;&lt;/LI&gt;
&lt;LI data-end="1008" data-start="983" data-section-id="jtjtmt"&gt;&lt;STRONG data-end="997" data-start="985"&gt;Disabled&lt;/STRONG&gt; → no alert&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1098" data-start="1010"&gt;Differences in this setting across profiles will directly cause inconsistent detections.&lt;/P&gt;
&lt;H4 data-end="1149" data-start="1105" data-section-id="17hy98f"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 data-end="1149" data-start="1105" data-section-id="17hy98f"&gt;3. Regional WildFire Verdict Differences&lt;/H4&gt;
&lt;P data-end="1197" data-start="1150"&gt;Cortex XDR uses &lt;STRONG data-end="1196" data-start="1166"&gt;regional WildFire verdicts&lt;/STRONG&gt;.&lt;/P&gt;
&lt;UL data-end="1300" data-start="1199"&gt;
&lt;LI data-end="1300" data-start="1199" data-section-id="1cgoin8"&gt;The same file hash may be:
&lt;UL data-end="1300" data-start="1230"&gt;
&lt;LI data-end="1268" data-start="1230" data-section-id="vmicd5"&gt;&lt;EM data-end="1254" data-start="1232"&gt;Malicious/Suspicious&lt;/EM&gt; in one region&lt;/LI&gt;
&lt;LI data-end="1300" data-start="1271" data-section-id="1s58i5m"&gt;&lt;EM data-end="1289" data-start="1273"&gt;Benign/Unknown&lt;/EM&gt; in another&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1392" data-start="1302"&gt;This can lead to different detection outcomes across geographically distributed endpoints.&lt;/P&gt;
&lt;H4 data-end="1422" data-start="1399" data-section-id="1krnc71"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 data-end="1422" data-start="1399" data-section-id="1krnc71"&gt;4. Alert Exclusions&lt;/H4&gt;
&lt;P data-end="1475" data-start="1423"&gt;Detection may still occur, but alerts can be hidden.&lt;/P&gt;
&lt;UL data-end="1630" data-start="1477"&gt;
&lt;LI data-end="1630" data-start="1477" data-section-id="1h3832j"&gt;If an &lt;STRONG data-end="1504" data-start="1485"&gt;Alert Exclusion&lt;/STRONG&gt; exists for:
&lt;UL data-end="1630" data-start="1519"&gt;
&lt;LI data-end="1546" data-start="1519" data-section-id="1r8tjor"&gt;The AnyDesk file/path, or&lt;/LI&gt;
&lt;LI data-end="1630" data-start="1549" data-section-id="11x2p2z"&gt;The &lt;STRONG data-end="1579" data-start="1555"&gt;“Detected (Scanned)”&lt;/STRONG&gt; action&lt;BR data-end="1589" data-start="1586" /&gt;→ The alert is suppressed in the console.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="1671" data-start="1637" data-section-id="7orm5g"&gt;5. Digital Signer Restrictions&lt;/H4&gt;
&lt;P data-end="1721" data-start="1672"&gt;Executables can be flagged based on signer trust.&lt;/P&gt;
&lt;UL data-end="1850" data-start="1723"&gt;
&lt;LI data-end="1850" data-start="1723" data-section-id="1ds6ilr"&gt;If AnyDesk’s signer is:
&lt;UL data-end="1850" data-start="1751"&gt;
&lt;LI data-end="1764" data-start="1751" data-section-id="b7jio8"&gt;Not trusted&lt;/LI&gt;
&lt;LI data-end="1850" data-start="1767" data-section-id="6eoxt"&gt;Explicitly restricted&lt;BR data-end="1793" data-start="1790" /&gt;→ The file may be marked as suspicious on some endpoints.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="1899" data-start="1857" data-section-id="1jvqinv"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 data-end="1899" data-start="1857" data-section-id="1jvqinv"&gt;6. Path Sensitivity (Downloads / Temp)&lt;/H4&gt;
&lt;P data-end="1978" data-start="1900"&gt;Files executed from &lt;STRONG data-end="1947" data-start="1920"&gt;higher-risk directories&lt;/STRONG&gt; are more likely to be flagged.&lt;/P&gt;
&lt;P data-end="1989" data-start="1980"&gt;Examples:&lt;/P&gt;
&lt;UL data-end="2038" data-start="1990"&gt;
&lt;LI data-end="2019" data-start="1990" data-section-id="11jr8e3"&gt;&lt;CODE data-end="2019" data-start="1992"&gt;C:\Users\&amp;lt;user&amp;gt;\Downloads&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI data-end="2038" data-start="2020" data-section-id="1hpl13f"&gt;Temp directories&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="2053" data-start="2040"&gt;Same file in:&lt;/P&gt;
&lt;UL data-end="2137" data-start="2054"&gt;
&lt;LI data-end="2093" data-start="2054" data-section-id="1sztf0c"&gt;&lt;STRONG data-end="2069" data-start="2056"&gt;Downloads&lt;/STRONG&gt; → more likely flagged&lt;/LI&gt;
&lt;LI data-end="2137" data-start="2094" data-section-id="21m56u"&gt;&lt;STRONG data-end="2113" data-start="2096"&gt;Program Files&lt;/STRONG&gt; → less likely flagged&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="2180" data-start="2144" data-section-id="t4jg89"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 data-end="2180" data-start="2144" data-section-id="t4jg89"&gt;Recommended Troubleshooting Steps&lt;/H4&gt;
&lt;H4 data-end="2211" data-start="2182" data-section-id="opaxt6"&gt;1. Check WildFire Verdict&lt;/H4&gt;
&lt;UL data-end="2342" data-start="2212"&gt;
&lt;LI data-end="2254" data-start="2212" data-section-id="mz7we0"&gt;Search the &lt;STRONG data-end="2240" data-start="2225"&gt;SHA256 hash&lt;/STRONG&gt; in Cortex XDR&lt;/LI&gt;
&lt;LI data-end="2342" data-start="2255" data-section-id="wbclhf"&gt;Confirm:
&lt;UL data-end="2342" data-start="2268"&gt;
&lt;LI data-end="2321" data-start="2268" data-section-id="13w0jbt"&gt;Verdict (Malicious / Suspicious / Unknown / Benign)&lt;/LI&gt;
&lt;LI data-end="2342" data-start="2324" data-section-id="2bh00q"&gt;Confidence level&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="2389" data-start="2349" data-section-id="f4ywuq"&gt;2. Compare Malware Security Profiles&lt;/H4&gt;
&lt;P data-end="2452" data-start="2390"&gt;Review profiles assigned to affected vs. unaffected endpoints:&lt;/P&gt;
&lt;UL data-end="2630" data-start="2454"&gt;
&lt;LI data-end="2479" data-start="2454" data-section-id="1trf66x"&gt;On-demand scan settings&lt;/LI&gt;
&lt;LI data-end="2509" data-start="2480" data-section-id="d710rs"&gt;Periodic scan configuration&lt;/LI&gt;
&lt;LI data-end="2590" data-start="2510" data-section-id="xcytba"&gt;Local Analysis behavior for:
&lt;UL data-end="2590" data-start="2543"&gt;
&lt;LI data-end="2558" data-start="2543" data-section-id="1qw4t91"&gt;Unknown files&lt;/LI&gt;
&lt;LI data-end="2590" data-start="2561" data-section-id="1q42bgp"&gt;Low-confidence benign files&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI data-end="2630" data-start="2591" data-section-id="14zwz1z"&gt;&lt;STRONG data-end="2622" data-start="2593"&gt;Treat Grayware as Malware&lt;/STRONG&gt; setting&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="2667" data-start="2637" data-section-id="1p76kio"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 data-end="2667" data-start="2637" data-section-id="1p76kio"&gt;3. Review Alert Exclusions&lt;/H4&gt;
&lt;P data-end="2680" data-start="2668"&gt;Navigate to:&lt;/P&gt;
&lt;UL data-end="2757" data-start="2681"&gt;
&lt;LI data-end="2757" data-start="2681" data-section-id="1kord3u"&gt;&lt;STRONG data-end="2757" data-start="2683"&gt;Settings → Configuration → Exception Configurations → Alert Exclusions&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="2785" data-start="2759"&gt;Check for rules affecting:&lt;/P&gt;
&lt;UL data-end="2842" data-start="2786"&gt;
&lt;LI data-end="2812" data-start="2786" data-section-id="9wk5cm"&gt;AnyDesk filename or path&lt;/LI&gt;
&lt;LI data-end="2842" data-start="2813" data-section-id="x9nkz"&gt;“Detected (Scanned)” alerts&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="2886" data-start="2849" data-section-id="1l0tuka"&gt;4. Verify Digital Signer Handling&lt;/H4&gt;
&lt;UL data-end="3038" data-start="2887"&gt;
&lt;LI data-end="2910" data-start="2887" data-section-id="51qqj6"&gt;Inspect alert details&lt;/LI&gt;
&lt;LI data-end="3038" data-start="2911" data-section-id="xcbzpb"&gt;If triggered by signer restriction:
&lt;UL data-end="3038" data-start="2951"&gt;
&lt;LI data-end="3038" data-start="2951" data-section-id="1p5zz5r"&gt;Add the AnyDesk signer to &lt;STRONG data-end="2998" data-start="2979"&gt;Trusted Signers&lt;/STRONG&gt; in the Malware Profile (if appropriate)&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 data-end="3070" data-start="3045" data-section-id="o7h2xs"&gt;5. Examine Agent Logs&lt;/H4&gt;
&lt;P data-end="3097" data-start="3071"&gt;If inconsistency persists:&lt;/P&gt;
&lt;UL data-end="3259" data-start="3099"&gt;
&lt;LI data-end="3138" data-start="3099" data-section-id="kzu7t0"&gt;Collect a &lt;STRONG data-end="3138" data-start="3111"&gt;Tech Support File (TSF)&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI data-end="3259" data-start="3139" data-section-id="8xkiwb"&gt;Review &lt;CODE data-end="3160" data-start="3148"&gt;trapsd.log&lt;/CODE&gt; for:
&lt;UL data-end="3259" data-start="3168"&gt;
&lt;LI data-end="3208" data-start="3168" data-section-id="1hw4dk2"&gt;Verdict codes (e.g., unknown verdicts)&lt;/LI&gt;
&lt;LI data-end="3259" data-start="3211" data-section-id="1hrfjhs"&gt;Connectivity issues preventing verdict updates.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2026 14:21:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/inconsistent-anydesk-detection-in-cortex-xdr/m-p/1250726#M9210</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-03-23T14:21:46Z</dc:date>
    </item>
  </channel>
</rss>

