<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic global protect whoami in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-whoami/m-p/596741#M5770</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am seeing a weird activity from globalprotect agents where the agent is trying to execute wa3_3rd_party_host.32.exe&lt;/P&gt;
&lt;P&gt;and the agent after that is executing whoami command.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS: the HIP policy is disabled on the firewall&lt;/P&gt;</description>
    <pubDate>Wed, 04 Sep 2024 11:37:25 GMT</pubDate>
    <dc:creator>BARaha</dc:creator>
    <dc:date>2024-09-04T11:37:25Z</dc:date>
    <item>
      <title>global protect whoami</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-whoami/m-p/596741#M5770</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am seeing a weird activity from globalprotect agents where the agent is trying to execute wa3_3rd_party_host.32.exe&lt;/P&gt;
&lt;P&gt;and the agent after that is executing whoami command.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS: the HIP policy is disabled on the firewall&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2024 11:37:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-whoami/m-p/596741#M5770</guid>
      <dc:creator>BARaha</dc:creator>
      <dc:date>2024-09-04T11:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: global protect whoami</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-whoami/m-p/597449#M5802</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/87335"&gt;@BARaha&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;wa3_3rd_party_host.32.exe is definitely not a standard or commonly recognized executable associated with GlobalProtect. I would recommend to take a look at the host and determine what the .exe is used for and run a scan. In the mean time, monitor the connections made on that particular host through the monitor traffic as well.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Btw, which panos version are you running on your firewall ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 00:44:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-whoami/m-p/597449#M5802</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-09-11T00:44:12Z</dc:date>
    </item>
  </channel>
</rss>

