<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: On-write file examination / cross-platform examination for Linux in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-file-examination-cross-platform-examination-for-linux/m-p/1255131#M9357</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/159504"&gt;@andreal&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the local wf_verdicts.db SQLite database for Cortex XDR agents (including Linux and macOS), the verdict value '6' technically maps to UnsupportedFileType .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;WinSCP (using SFTP/SCP protocols) is considered a high-volume I/O process that can trigger the "noisy process" protection mechanism (LRU throttling) in Cortex XDR Agent 9.1.0 for Linux, potentially causing "On-Write File Examination" to be bypassed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
    <pubDate>Mon, 01 Jun 2026 14:52:52 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-06-01T14:52:52Z</dc:date>
    <item>
      <title>On-write file examination / cross-platform examination for Linux</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-file-examination-cross-platform-examination-for-linux/m-p/1255130#M9356</link>
      <description>&lt;P&gt;Dear LIVEcommunity&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone been able to test out the new Linux / MacOS cross-platform examination module? I created a new Linux Malware Profile and set the "On-write File Examination" for "Portable executable files (Windows)" to Enabled, applied it to a policy for my Linux endpoint, waited for the policy to apply and then copied a WildFire Test PE (Windows executable which should always trigger an alert) from a Windows to my Linux host via WinSCP. I did not get any Cortex XDR Alerts, and a manually initiated Cortex XDR malware scan on the Linux endpoint also did not detect the file. The Linux host has Cortex XDR Agent 9.1.0, the feature should be supported with version 8.9+&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A closer inspection of the "wf_verdicts.db" shows my WildFire Test PE Windows Executable has a Verdict with value 6, which I cannot find in the Log Format documentation (only values 0,1,2,4,99 are defined):&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Documentation/Log-formats" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Documentation/Log-formats&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm curious to see if anyone was able to successfully test this feature.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2026 14:42:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-file-examination-cross-platform-examination-for-linux/m-p/1255130#M9356</guid>
      <dc:creator>andreal</dc:creator>
      <dc:date>2026-06-01T14:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: On-write file examination / cross-platform examination for Linux</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-file-examination-cross-platform-examination-for-linux/m-p/1255131#M9357</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/159504"&gt;@andreal&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the local wf_verdicts.db SQLite database for Cortex XDR agents (including Linux and macOS), the verdict value '6' technically maps to UnsupportedFileType .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;WinSCP (using SFTP/SCP protocols) is considered a high-volume I/O process that can trigger the "noisy process" protection mechanism (LRU throttling) in Cortex XDR Agent 9.1.0 for Linux, potentially causing "On-Write File Examination" to be bypassed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2026 14:52:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-file-examination-cross-platform-examination-for-linux/m-p/1255131#M9357</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-06-01T14:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: On-write file examination / cross-platform examination for Linux</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-file-examination-cross-platform-examination-for-linux/m-p/1255132#M9358</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/241098"&gt;@susekar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I appreciate the quick response! Thanks for the insight in to the verdict value 6, very interesting.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As the filetype is not supported, I upgraded to Cortex XDR Agent Version to 9.2.0 (because it's a feature from the latest release - I assume the on-write-protection is a feature for Cortex XDR Agent 8.9+ but cross-platform-examination only a 9.2.0 feature) and tried to re-produce the issue. Again, no alert was created.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, now the verdict value changed to '3' for the new file.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any other protocol I could use to test out the cross-platform-examination if WinSCP is bypassing the "On-Write File Examination"?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2026 15:13:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/on-write-file-examination-cross-platform-examination-for-linux/m-p/1255132#M9358</guid>
      <dc:creator>andreal</dc:creator>
      <dc:date>2026-06-01T15:13:45Z</dc:date>
    </item>
  </channel>
</rss>

