<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR and Sandboxie in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-and-sandboxie/m-p/1257136#M9399</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/663134521"&gt;@M.Wempen&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="244" data-start="50"&gt;Based on the behavior described, this appears to be a compatibility issue between Sandboxie's DLL injection/hooking mechanism and Cortex XDR's process injection and exploit protection framework.&lt;/P&gt;
&lt;P data-end="244" data-start="50"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="584" data-start="249"&gt;The main indicator is that the applications launch successfully once a &lt;STRONG data-end="358" data-start="320"&gt;"Disable Injection and Prevention"&lt;/STRONG&gt; rule is applied. Since Sandboxie relies on injecting components into processes running inside the sandbox, Cortex XDR may be interfering with that initialization process even though no security alert or incident is generated.&lt;/P&gt;
&lt;P data-end="584" data-start="249"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="611" data-start="589"&gt;A few recommendations:&lt;/P&gt;
&lt;UL data-end="1145" data-start="616"&gt;
&lt;LI data-end="712" data-start="616" data-section-id="c6t4z2"&gt;Verify that both the Cortex XDR agent and Sandboxie are running the latest supported versions.&lt;/LI&gt;
&lt;LI data-end="849" data-start="715" data-section-id="4gn962"&gt;Review Cortex XDR agent logs and diagnostic bundles for any injection- or exploit-protection-related entries during process startup.&lt;/LI&gt;
&lt;LI data-end="951" data-start="852" data-section-id="1ag94ll"&gt;Use ProcMon or similar tools to compare process creation behavior with and without the exception.&lt;/LI&gt;
&lt;LI data-end="1143" data-start="954" data-section-id="1crol3t"&gt;If possible, create a narrowly scoped exception for the Sandboxie service/broker process rather than excluding every sandboxed application (e.g., &lt;CODE data-end="1114" data-start="1102"&gt;msedge.exe&lt;/CODE&gt;, &lt;CODE data-end="1125" data-start="1116"&gt;cmd.exe&lt;/CODE&gt;, &lt;CODE data-end="1141" data-start="1127"&gt;explorer.exe&lt;/CODE&gt;).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1502" data-start="1148"&gt;Since no alerts are being generated, this is likely a product compatibility issue rather than a standard prevention event. If the issue continues, I would recommend opening a Palo Alto Support case and providing agent diagnostics, Cortex XDR version, Windows build, and Sandboxie version so they can determine whether this is a known compatibility issue.&lt;/P&gt;
&lt;P data-end="1502" data-start="1148"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help other users by clicking ‘Accept as Solution’ if a post helps solve your problem.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/how-and-why-to-accept-solutions/ba-p/553827" target="_blank"&gt;Read more about how and why to accept solutions.&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-end="1502" data-start="1148"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1502" data-start="1148"&gt;Best Regards,&lt;/P&gt;
&lt;P data-end="1502" data-start="1148"&gt;Vinothkumar C&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jun 2026 12:35:43 GMT</pubDate>
    <dc:creator>Vinothkumar_SBA</dc:creator>
    <dc:date>2026-06-23T12:35:43Z</dc:date>
    <item>
      <title>Cortex XDR and Sandboxie</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-and-sandboxie/m-p/1257132#M9397</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="3"&gt;We have installed Cortex XDR on a VM that also runs a sandbox tool (Sandboxie). As long as Cortex XDR is enabled, processes cannot be started within the sandbox (e.g., &lt;CODE data-index-in-node="168" data-path-to-node="3"&gt;msedge.exe&lt;/CODE&gt;, &lt;CODE data-index-in-node="180" data-path-to-node="3"&gt;cmd.exe&lt;/CODE&gt;, &lt;CODE data-index-in-node="189" data-path-to-node="3"&gt;explorer.exe&lt;/CODE&gt;). It only works if I create a "Disable Injection and Prevention" rule for these processes.&lt;/P&gt;
&lt;P data-path-to-node="4"&gt;How can I resolve this permanently? I suspect the issue is that Cortex prevents process hooking. Interestingly, we don't see any security cases or alerts being generated for this in the console.&lt;/P&gt;
&lt;P data-path-to-node="4"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="4"&gt;Greetings and thank you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2026 11:26:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-and-sandboxie/m-p/1257132#M9397</guid>
      <dc:creator>M.Wempen</dc:creator>
      <dc:date>2026-06-23T11:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR and Sandboxie</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-and-sandboxie/m-p/1257136#M9399</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/663134521"&gt;@M.Wempen&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="244" data-start="50"&gt;Based on the behavior described, this appears to be a compatibility issue between Sandboxie's DLL injection/hooking mechanism and Cortex XDR's process injection and exploit protection framework.&lt;/P&gt;
&lt;P data-end="244" data-start="50"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="584" data-start="249"&gt;The main indicator is that the applications launch successfully once a &lt;STRONG data-end="358" data-start="320"&gt;"Disable Injection and Prevention"&lt;/STRONG&gt; rule is applied. Since Sandboxie relies on injecting components into processes running inside the sandbox, Cortex XDR may be interfering with that initialization process even though no security alert or incident is generated.&lt;/P&gt;
&lt;P data-end="584" data-start="249"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="611" data-start="589"&gt;A few recommendations:&lt;/P&gt;
&lt;UL data-end="1145" data-start="616"&gt;
&lt;LI data-end="712" data-start="616" data-section-id="c6t4z2"&gt;Verify that both the Cortex XDR agent and Sandboxie are running the latest supported versions.&lt;/LI&gt;
&lt;LI data-end="849" data-start="715" data-section-id="4gn962"&gt;Review Cortex XDR agent logs and diagnostic bundles for any injection- or exploit-protection-related entries during process startup.&lt;/LI&gt;
&lt;LI data-end="951" data-start="852" data-section-id="1ag94ll"&gt;Use ProcMon or similar tools to compare process creation behavior with and without the exception.&lt;/LI&gt;
&lt;LI data-end="1143" data-start="954" data-section-id="1crol3t"&gt;If possible, create a narrowly scoped exception for the Sandboxie service/broker process rather than excluding every sandboxed application (e.g., &lt;CODE data-end="1114" data-start="1102"&gt;msedge.exe&lt;/CODE&gt;, &lt;CODE data-end="1125" data-start="1116"&gt;cmd.exe&lt;/CODE&gt;, &lt;CODE data-end="1141" data-start="1127"&gt;explorer.exe&lt;/CODE&gt;).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1502" data-start="1148"&gt;Since no alerts are being generated, this is likely a product compatibility issue rather than a standard prevention event. If the issue continues, I would recommend opening a Palo Alto Support case and providing agent diagnostics, Cortex XDR version, Windows build, and Sandboxie version so they can determine whether this is a known compatibility issue.&lt;/P&gt;
&lt;P data-end="1502" data-start="1148"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help other users by clicking ‘Accept as Solution’ if a post helps solve your problem.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/how-and-why-to-accept-solutions/ba-p/553827" target="_blank"&gt;Read more about how and why to accept solutions.&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-end="1502" data-start="1148"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1502" data-start="1148"&gt;Best Regards,&lt;/P&gt;
&lt;P data-end="1502" data-start="1148"&gt;Vinothkumar C&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2026 12:35:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-and-sandboxie/m-p/1257136#M9399</guid>
      <dc:creator>Vinothkumar_SBA</dc:creator>
      <dc:date>2026-06-23T12:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR and Sandboxie</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-and-sandboxie/m-p/1257144#M9400</link>
      <description>&lt;P&gt;For your recommendation&lt;BR /&gt;"If possible, create a narrowly scoped exception for the Sandboxie service/broker process rather than excluding every sandboxed application (e.g.,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE data-start="1102" data-end="1114"&gt;msedge.exe&lt;/CODE&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE data-start="1116" data-end="1125"&gt;cmd.exe&lt;/CODE&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE data-start="1127" data-end="1141"&gt;explorer.exe&lt;/CODE&gt;)."&lt;BR /&gt;&lt;BR /&gt;Which exception should i create? How can i determine which exception is necessary&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2026 13:27:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-and-sandboxie/m-p/1257144#M9400</guid>
      <dc:creator>M.Wempen</dc:creator>
      <dc:date>2026-06-23T13:27:02Z</dc:date>
    </item>
  </channel>
</rss>

