<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Understanding Inline Cloud Analysis C2 Detections and False Positives in Cortex XDR in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/understanding-inline-cloud-analysis-c2-detections-and-false/m-p/1256462#M6967</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am currently investigating several Cortex XDR incidents that originate from Palo Alto Networks Firewall Security Profiles, specifically detections related to Inline Cloud Analysis, Anti-Spyware C2 classifications.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I am trying to better understand is why a relatively large amount of legitimate-looking web traffic is being classified as C2 communication and then forwarded into Cortex XDR as incidents.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In some cases, the traffic seems to be related to normal website activity, for example connections to well-known websites such as LinkedIn or embedded third-party services loaded by those sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the Cortex side, I can see the incident, but for proper troubleshooting I need to better understand the original source of the detection on the firewall side, especially the Anti-Spyware profile and Inline Cloud Analysis behavior.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My current assumption is that some modern web traffic patterns may look similar to C2-like behavior, for example:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;embedded JavaScript loading additional content dynamically&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;recurring background requests&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;small POST requests&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;encoded URL parameters&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;tracking, analytics, or telemetry endpoints&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;communication with third-party domains or CDNs&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;WebSocket, long-polling, or beaconing-like behavior&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I would like to understand which characteristics typically cause Inline Cloud Analysis to classify traffic as C2 and what others are using to distinguish real C2 activity from false positives in daily operations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any practical experience, investigation approach, or recommended fields to look at would be very helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Tobias&lt;/P&gt;</description>
    <pubDate>Tue, 16 Jun 2026 08:13:36 GMT</pubDate>
    <dc:creator>tobias.fink</dc:creator>
    <dc:date>2026-06-16T08:13:36Z</dc:date>
    <item>
      <title>Understanding Inline Cloud Analysis C2 Detections and False Positives in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/understanding-inline-cloud-analysis-c2-detections-and-false/m-p/1256462#M6967</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am currently investigating several Cortex XDR incidents that originate from Palo Alto Networks Firewall Security Profiles, specifically detections related to Inline Cloud Analysis, Anti-Spyware C2 classifications.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I am trying to better understand is why a relatively large amount of legitimate-looking web traffic is being classified as C2 communication and then forwarded into Cortex XDR as incidents.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In some cases, the traffic seems to be related to normal website activity, for example connections to well-known websites such as LinkedIn or embedded third-party services loaded by those sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the Cortex side, I can see the incident, but for proper troubleshooting I need to better understand the original source of the detection on the firewall side, especially the Anti-Spyware profile and Inline Cloud Analysis behavior.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My current assumption is that some modern web traffic patterns may look similar to C2-like behavior, for example:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;embedded JavaScript loading additional content dynamically&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;recurring background requests&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;small POST requests&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;encoded URL parameters&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;tracking, analytics, or telemetry endpoints&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;communication with third-party domains or CDNs&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;WebSocket, long-polling, or beaconing-like behavior&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I would like to understand which characteristics typically cause Inline Cloud Analysis to classify traffic as C2 and what others are using to distinguish real C2 activity from false positives in daily operations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any practical experience, investigation approach, or recommended fields to look at would be very helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Tobias&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2026 08:13:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/understanding-inline-cloud-analysis-c2-detections-and-false/m-p/1256462#M6967</guid>
      <dc:creator>tobias.fink</dc:creator>
      <dc:date>2026-06-16T08:13:36Z</dc:date>
    </item>
  </channel>
</rss>

