<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False Positives  Microsoft Teams Large Upload in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/false-positives-microsoft-teams-large-upload/m-p/571199#M2948</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Normally, preprocessing script should discard those incidents if configured properly. I need to see your script and the raw data coming from the incident to be able to help. If you are still facing the issue, please try to provide relevant part from incident data with demisto.incident() and your preprocessing script.&lt;/P&gt;</description>
    <pubDate>Fri, 29 Dec 2023 09:14:24 GMT</pubDate>
    <dc:creator>gyldz</dc:creator>
    <dc:date>2023-12-29T09:14:24Z</dc:date>
    <item>
      <title>False Positives  Microsoft Teams Large Upload</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/false-positives-microsoft-teams-large-upload/m-p/566865#M2853</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I need your help.&lt;/P&gt;
&lt;P&gt;We are receiving alerts "XDR Incident 945 - 'Large upload (generic)' generated by #XDR Analytics detected...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Basically, this appears when the user makes a call, shares documents, or shares their screen (using Microsoft Teams).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the #XSOAR event I can see that the processname is ms-teams.exe and the destination ip is from Microsoft Azure networks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know this is related to screen sharing because it has happened to my user/laptop.&lt;/P&gt;
&lt;P&gt;I tried to create a pre-process rule to do autoclose....in the test... pre-process it works, in practice it doesn't.&lt;BR /&gt;Does this situation happen to everyone?&lt;BR /&gt;any suggestion??&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 12:11:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/false-positives-microsoft-teams-large-upload/m-p/566865#M2853</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2023-11-23T12:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: False Positives  Microsoft Teams Large Upload</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/false-positives-microsoft-teams-large-upload/m-p/571199#M2948</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Normally, preprocessing script should discard those incidents if configured properly. I need to see your script and the raw data coming from the incident to be able to help. If you are still facing the issue, please try to provide relevant part from incident data with demisto.incident() and your preprocessing script.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2023 09:14:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/false-positives-microsoft-teams-large-upload/m-p/571199#M2948</guid>
      <dc:creator>gyldz</dc:creator>
      <dc:date>2023-12-29T09:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: False Positives  Microsoft Teams Large Upload</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/false-positives-microsoft-teams-large-upload/m-p/571618#M2958</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I've found the problem... missing parameter on incoming mapper.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 15:11:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/false-positives-microsoft-teams-large-upload/m-p/571618#M2958</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-01-03T15:11:24Z</dc:date>
    </item>
  </channel>
</rss>

