<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Understanding Inline Cloud Analysis C2 Detections and False Positives in Cortex XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/understanding-inline-cloud-analysis-c2-detections-and-false/m-p/1256714#M9389</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/298618815"&gt;@tobias.fink&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="301" data-start="0"&gt;The classification of legitimate web traffic as Command and Control (C2) by the Next-Generation Firewall (NGFW) Inline Cloud Analysis engine, and its subsequent appearance in Cortex XDR, is a recognized trend often driven by connectivity latency, statistical rarity, or shared infrastructure patterns.&lt;/P&gt;
&lt;P data-end="301" data-start="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="349" data-start="303" data-section-id="4cxu0q"&gt;Why Legitimate Traffic is Classified as C2&lt;/H4&gt;
&lt;P data-end="432" data-start="351"&gt;Several technical factors and modern web patterns contribute to these detections:&lt;/P&gt;
&lt;P data-end="432" data-start="351"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="816" data-start="434"&gt;&lt;STRONG data-end="464" data-start="434"&gt;-Cloud Connectivity Latency&lt;/STRONG&gt;&lt;BR data-end="467" data-start="464" /&gt;A significant cause for Inline-Cloud-C2 misclassification is latency or unstable network paths between the NGFW and the cloud classification service. If the cloud service cannot provide a verdict within the configured timeframe, the firewall may default to a high-severity C2 alert for Unknown-TCP traffic, even if the traffic is eventually allowed.&lt;/P&gt;
&lt;P data-end="816" data-start="434"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1185" data-start="818"&gt;&lt;STRONG data-end="855" data-start="818"&gt;-Statistical Rarity (Rare Domains)&lt;/STRONG&gt;&lt;BR data-end="858" data-start="855" /&gt;Cortex XDR Analytics frequently flags legitimate third-party analytics and CDN endpoints because they appear statistically rare within a specific environment. Rules such as &lt;STRONG data-end="1085" data-start="1031"&gt;Abnormal Recurring Communications to a Rare Domain&lt;/STRONG&gt; can trigger when benign domains exhibit periodic communication patterns that resemble C2 beaconing.&lt;/P&gt;
&lt;P data-end="1185" data-start="818"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1524" data-start="1187"&gt;&lt;STRONG data-end="1239" data-start="1187"&gt;-Shared CDN Infrastructure (DNS Stitching Errors)&lt;/STRONG&gt;&lt;BR data-end="1242" data-start="1239" /&gt;Multiple legitimate domains often share a single IP address on major CDNs or cloud platforms. The Analytics engine may incorrectly attribute traffic to a rare or suspicious domain when different domains resolve to the same shared IP address, resulting in DNS stitching inaccuracies.&lt;/P&gt;
&lt;P data-end="1524" data-start="1187"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1737" data-start="1526"&gt;&lt;STRONG data-end="1555" data-start="1526"&gt;-Specific Service Patterns&lt;/STRONG&gt;&lt;BR data-end="1558" data-start="1555" /&gt;Authentication traffic from trusted services, such as Okta, can occasionally be misclassified as C2 activity when Inline Cloud Analysis is enabled within the Anti-Spyware profile.&lt;/P&gt;
&lt;P data-end="1737" data-start="1526"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1737" data-start="1526"&gt;---------------------------------&lt;/P&gt;
&lt;H4 data-end="1779" data-start="1739" data-section-id="1flnczy"&gt;Investigation Approach in Cortex XDR&lt;/H4&gt;
&lt;P data-end="1880" data-start="1781"&gt;To distinguish genuine C2 activity from false positives, analysts should follow the workflow below:&lt;/P&gt;
&lt;P data-end="1880" data-start="1781"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="2079" data-start="1882"&gt;&lt;STRONG data-end="1909" data-start="1882"&gt;Verify the Alert Source&lt;/STRONG&gt;&lt;BR data-end="1912" data-start="1909" /&gt;Confirm that the detection originated from the firewall by checking the &lt;CODE data-end="1998" data-start="1984"&gt;alert_source&lt;/CODE&gt; field (typically &lt;STRONG data-end="2022" data-start="2016"&gt;FW&lt;/STRONG&gt;) and the &lt;CODE data-end="2046" data-start="2032"&gt;data_sources&lt;/CODE&gt; field (typically &lt;STRONG data-end="2077" data-start="2064"&gt;PANW/NGFW&lt;/STRONG&gt;).&lt;/P&gt;
&lt;P data-end="2079" data-start="1882"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="2204" data-start="2081"&gt;&lt;STRONG data-end="2104" data-start="2081"&gt;Retrieve Debug Data&lt;/STRONG&gt;&lt;BR data-end="2107" data-start="2104" /&gt;To extract detailed metadata such as the Threat ID, Firewall Serial Number, and Security Profile:&lt;/P&gt;
&lt;OL data-end="2314" data-start="2206"&gt;
&lt;LI data-end="2242" data-start="2206" data-section-id="1pnrhki"&gt;Navigate to the &lt;STRONG data-end="2235" data-start="2225"&gt;Alerts&lt;/STRONG&gt; table.&lt;/LI&gt;
&lt;LI data-end="2287" data-start="2243" data-section-id="1brtglz"&gt;Press &lt;STRONG data-end="2273" data-start="2252"&gt;ALT + Right-click&lt;/STRONG&gt; on the alert.&lt;/LI&gt;
&lt;LI data-end="2314" data-start="2288" data-section-id="hrw8ip"&gt;Select &lt;STRONG data-end="2313" data-start="2298"&gt;Debug Alert&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-end="2630" data-start="2316"&gt;&lt;STRONG data-end="2337" data-start="2316"&gt;Analyze Causality:&lt;/STRONG&gt;&lt;BR data-end="2340" data-start="2337" /&gt;Review the &lt;STRONG data-end="2369" data-start="2351"&gt;Causality Card&lt;/STRONG&gt; or &lt;STRONG data-end="2392" data-start="2373"&gt;Causality Chain&lt;/STRONG&gt; to determine whether the network activity can be correlated with a local endpoint process. This helps identify whether the traffic originated from a legitimate application (such as a web browser) or from an unknown or suspicious process.&lt;/P&gt;
&lt;P data-end="2630" data-start="2316"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="2729" data-start="2632"&gt;&lt;STRONG data-end="2660" data-start="2632"&gt;Query Raw Logs Using XQL&lt;/STRONG&gt;&lt;BR data-end="2663" data-start="2660" /&gt;Inspect the raw traffic and threat data in the following datasets:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;panw_ngfw_threat_raw&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;panw_ngfw_traffic_raw&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;panw_ngfw_url_raw&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;SPAN&gt;Reviewing these datasets can provide additional context around the communication pattern, destination, URL categorization, and firewall action, helping to determine whether the alert represents a true threat or a false positive.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
    <pubDate>Thu, 18 Jun 2026 13:20:50 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-06-18T13:20:50Z</dc:date>
    <item>
      <title>Understanding Inline Cloud Analysis C2 Detections and False Positives in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/understanding-inline-cloud-analysis-c2-detections-and-false/m-p/1256462#M9387</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am currently investigating several Cortex XDR incidents that originate from Palo Alto Networks Firewall Security Profiles, specifically detections related to Inline Cloud Analysis, Anti-Spyware C2 classifications.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I am trying to better understand is why a relatively large amount of legitimate-looking web traffic is being classified as C2 communication and then forwarded into Cortex XDR as incidents.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In some cases, the traffic seems to be related to normal website activity, for example connections to well-known websites such as LinkedIn or embedded third-party services loaded by those sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the Cortex side, I can see the incident, but for proper troubleshooting I need to better understand the original source of the detection on the firewall side, especially the Anti-Spyware profile and Inline Cloud Analysis behavior.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My current assumption is that some modern web traffic patterns may look similar to C2-like behavior, for example:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;embedded JavaScript loading additional content dynamically&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;recurring background requests&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;small POST requests&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;encoded URL parameters&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;tracking, analytics, or telemetry endpoints&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;communication with third-party domains or CDNs&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;WebSocket, long-polling, or beaconing-like behavior&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I would like to understand which characteristics typically cause Inline Cloud Analysis to classify traffic as C2 and what others are using to distinguish real C2 activity from false positives in daily operations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any practical experience, investigation approach, or recommended fields to look at would be very helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Tobias&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2026 08:13:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/understanding-inline-cloud-analysis-c2-detections-and-false/m-p/1256462#M9387</guid>
      <dc:creator>tobias.fink</dc:creator>
      <dc:date>2026-06-16T08:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Inline Cloud Analysis C2 Detections and False Positives in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/understanding-inline-cloud-analysis-c2-detections-and-false/m-p/1256714#M9389</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/298618815"&gt;@tobias.fink&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="301" data-start="0"&gt;The classification of legitimate web traffic as Command and Control (C2) by the Next-Generation Firewall (NGFW) Inline Cloud Analysis engine, and its subsequent appearance in Cortex XDR, is a recognized trend often driven by connectivity latency, statistical rarity, or shared infrastructure patterns.&lt;/P&gt;
&lt;P data-end="301" data-start="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="349" data-start="303" data-section-id="4cxu0q"&gt;Why Legitimate Traffic is Classified as C2&lt;/H4&gt;
&lt;P data-end="432" data-start="351"&gt;Several technical factors and modern web patterns contribute to these detections:&lt;/P&gt;
&lt;P data-end="432" data-start="351"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="816" data-start="434"&gt;&lt;STRONG data-end="464" data-start="434"&gt;-Cloud Connectivity Latency&lt;/STRONG&gt;&lt;BR data-end="467" data-start="464" /&gt;A significant cause for Inline-Cloud-C2 misclassification is latency or unstable network paths between the NGFW and the cloud classification service. If the cloud service cannot provide a verdict within the configured timeframe, the firewall may default to a high-severity C2 alert for Unknown-TCP traffic, even if the traffic is eventually allowed.&lt;/P&gt;
&lt;P data-end="816" data-start="434"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1185" data-start="818"&gt;&lt;STRONG data-end="855" data-start="818"&gt;-Statistical Rarity (Rare Domains)&lt;/STRONG&gt;&lt;BR data-end="858" data-start="855" /&gt;Cortex XDR Analytics frequently flags legitimate third-party analytics and CDN endpoints because they appear statistically rare within a specific environment. Rules such as &lt;STRONG data-end="1085" data-start="1031"&gt;Abnormal Recurring Communications to a Rare Domain&lt;/STRONG&gt; can trigger when benign domains exhibit periodic communication patterns that resemble C2 beaconing.&lt;/P&gt;
&lt;P data-end="1185" data-start="818"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1524" data-start="1187"&gt;&lt;STRONG data-end="1239" data-start="1187"&gt;-Shared CDN Infrastructure (DNS Stitching Errors)&lt;/STRONG&gt;&lt;BR data-end="1242" data-start="1239" /&gt;Multiple legitimate domains often share a single IP address on major CDNs or cloud platforms. The Analytics engine may incorrectly attribute traffic to a rare or suspicious domain when different domains resolve to the same shared IP address, resulting in DNS stitching inaccuracies.&lt;/P&gt;
&lt;P data-end="1524" data-start="1187"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1737" data-start="1526"&gt;&lt;STRONG data-end="1555" data-start="1526"&gt;-Specific Service Patterns&lt;/STRONG&gt;&lt;BR data-end="1558" data-start="1555" /&gt;Authentication traffic from trusted services, such as Okta, can occasionally be misclassified as C2 activity when Inline Cloud Analysis is enabled within the Anti-Spyware profile.&lt;/P&gt;
&lt;P data-end="1737" data-start="1526"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1737" data-start="1526"&gt;---------------------------------&lt;/P&gt;
&lt;H4 data-end="1779" data-start="1739" data-section-id="1flnczy"&gt;Investigation Approach in Cortex XDR&lt;/H4&gt;
&lt;P data-end="1880" data-start="1781"&gt;To distinguish genuine C2 activity from false positives, analysts should follow the workflow below:&lt;/P&gt;
&lt;P data-end="1880" data-start="1781"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="2079" data-start="1882"&gt;&lt;STRONG data-end="1909" data-start="1882"&gt;Verify the Alert Source&lt;/STRONG&gt;&lt;BR data-end="1912" data-start="1909" /&gt;Confirm that the detection originated from the firewall by checking the &lt;CODE data-end="1998" data-start="1984"&gt;alert_source&lt;/CODE&gt; field (typically &lt;STRONG data-end="2022" data-start="2016"&gt;FW&lt;/STRONG&gt;) and the &lt;CODE data-end="2046" data-start="2032"&gt;data_sources&lt;/CODE&gt; field (typically &lt;STRONG data-end="2077" data-start="2064"&gt;PANW/NGFW&lt;/STRONG&gt;).&lt;/P&gt;
&lt;P data-end="2079" data-start="1882"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="2204" data-start="2081"&gt;&lt;STRONG data-end="2104" data-start="2081"&gt;Retrieve Debug Data&lt;/STRONG&gt;&lt;BR data-end="2107" data-start="2104" /&gt;To extract detailed metadata such as the Threat ID, Firewall Serial Number, and Security Profile:&lt;/P&gt;
&lt;OL data-end="2314" data-start="2206"&gt;
&lt;LI data-end="2242" data-start="2206" data-section-id="1pnrhki"&gt;Navigate to the &lt;STRONG data-end="2235" data-start="2225"&gt;Alerts&lt;/STRONG&gt; table.&lt;/LI&gt;
&lt;LI data-end="2287" data-start="2243" data-section-id="1brtglz"&gt;Press &lt;STRONG data-end="2273" data-start="2252"&gt;ALT + Right-click&lt;/STRONG&gt; on the alert.&lt;/LI&gt;
&lt;LI data-end="2314" data-start="2288" data-section-id="hrw8ip"&gt;Select &lt;STRONG data-end="2313" data-start="2298"&gt;Debug Alert&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-end="2630" data-start="2316"&gt;&lt;STRONG data-end="2337" data-start="2316"&gt;Analyze Causality:&lt;/STRONG&gt;&lt;BR data-end="2340" data-start="2337" /&gt;Review the &lt;STRONG data-end="2369" data-start="2351"&gt;Causality Card&lt;/STRONG&gt; or &lt;STRONG data-end="2392" data-start="2373"&gt;Causality Chain&lt;/STRONG&gt; to determine whether the network activity can be correlated with a local endpoint process. This helps identify whether the traffic originated from a legitimate application (such as a web browser) or from an unknown or suspicious process.&lt;/P&gt;
&lt;P data-end="2630" data-start="2316"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="2729" data-start="2632"&gt;&lt;STRONG data-end="2660" data-start="2632"&gt;Query Raw Logs Using XQL&lt;/STRONG&gt;&lt;BR data-end="2663" data-start="2660" /&gt;Inspect the raw traffic and threat data in the following datasets:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;panw_ngfw_threat_raw&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;panw_ngfw_traffic_raw&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;panw_ngfw_url_raw&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;SPAN&gt;Reviewing these datasets can provide additional context around the communication pattern, destination, URL categorization, and firewall action, helping to determine whether the alert represents a true threat or a false positive.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2026 13:20:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/understanding-inline-cloud-analysis-c2-detections-and-false/m-p/1256714#M9389</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-06-18T13:20:50Z</dc:date>
    </item>
  </channel>
</rss>

