<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article 规则名称为 &amp;quot;bioc.vulnerable_driver_dropped_$name &amp;quot;的BTP警报是否为假阳性检测？ in 配置和实施</title>
    <link>https://live.paloaltonetworks.com/t5/%E9%85%8D%E7%BD%AE%E5%92%8C%E5%AE%9E%E6%96%BD/%E8%A7%84%E5%88%99%E5%90%8D%E7%A7%B0%E4%B8%BA-quot-bioc-vulnerable-driver-dropped-name-quot/ta-p/527697</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;总结：&lt;/P&gt;
&lt;P&gt;这篇文章描述了BTP警报的情况，它的规则名称如下。&lt;BR /&gt;bioc.vulnerable_driver_dropped_$name&lt;BR /&gt;bioc.sync.vulnerable_driver_loaded_$name&lt;BR /&gt;bioc.sync.vulnerable_driver_by_original_name_loaded_$name&lt;BR /&gt;bioc.sync.vulnerable_driver_by_signer_name_loaded_$name&lt;BR /&gt;bioc.sync.malicious_driver_by_signer_name_loaded_$name&lt;BR /&gt;bioc.sync.malicious_driver_by_original_name_loaded__$name&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;环境：&lt;/P&gt;
&lt;DIV class="slds-form-element__control slds-grid itemBody" data-aura-rendered-by="100168:0"&gt;
&lt;DIV class="slds-rich-text-editor__output uiOutputRichText forceOutputRichText forceKnowledgeOutputRichTextForKnowledge" dir="ltr" data-aura-rendered-by="100160:0" data-aura-class="uiOutputRichText forceOutputRichText forceKnowledgeOutputRichTextForKnowledge"&gt;
&lt;UL data-aura-rendered-by="100161:0"&gt;
&lt;LI&gt;Cortex XDR for Windows&lt;/LI&gt;
&lt;LI&gt;Behavioral Threat Protection (BTP)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;答案：&lt;/P&gt;
&lt;P&gt;这不是一个假阳性检测。&lt;BR /&gt;这是一个易受攻击的驱动程序，正在被客户机器上的一个应用程序使用。所以我们阻止了它。&lt;BR /&gt;这个驱动程序可以被攻击者滥用，以获得权限的提升。&lt;BR /&gt;注意：如果一个规则名称有这些内容，它不是一个假阳性。它们也是由有漏洞的驱动文件引起的。&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="ckeditor_codeblock" data-aura-rendered-by="100190:0"&gt;&lt;SPAN&gt;bioc.vulnerable_driver_dropped_$name
bioc.sync.vulnerable_driver_loaded_$name
bioc.sync.vulnerable_driver_by_original_name_loaded_$name
bioc.sync.vulnerable_driver_by_signer_name_loaded_$name
bioc.sync.malicious_driver_by_signer_name_loaded_$name
bioc.sync.malicious_driver_by_original_name_loaded__$name&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Thu, 19 Jan 2023 11:53:03 GMT</pubDate>
    <dc:creator>juzhang</dc:creator>
    <dc:date>2023-01-19T11:53:03Z</dc:date>
    <item>
      <title>规则名称为 "bioc.vulnerable_driver_dropped_$name "的BTP警报是否为假阳性检测？</title>
      <link>https://live.paloaltonetworks.com/t5/%E9%85%8D%E7%BD%AE%E5%92%8C%E5%AE%9E%E6%96%BD/%E8%A7%84%E5%88%99%E5%90%8D%E7%A7%B0%E4%B8%BA-quot-bioc-vulnerable-driver-dropped-name-quot/ta-p/527697</link>
      <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;总结：&lt;/P&gt;
&lt;P&gt;这篇文章描述了BTP警报的情况，它的规则名称如下。&lt;BR /&gt;bioc.vulnerable_driver_dropped_$name&lt;BR /&gt;bioc.sync.vulnerable_driver_loaded_$name&lt;BR /&gt;bioc.sync.vulnerable_driver_by_original_name_loaded_$name&lt;BR /&gt;bioc.sync.vulnerable_driver_by_signer_name_loaded_$name&lt;BR /&gt;bioc.sync.malicious_driver_by_signer_name_loaded_$name&lt;BR /&gt;bioc.sync.malicious_driver_by_original_name_loaded__$name&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;环境：&lt;/P&gt;
&lt;DIV class="slds-form-element__control slds-grid itemBody" data-aura-rendered-by="100168:0"&gt;
&lt;DIV class="slds-rich-text-editor__output uiOutputRichText forceOutputRichText forceKnowledgeOutputRichTextForKnowledge" dir="ltr" data-aura-rendered-by="100160:0" data-aura-class="uiOutputRichText forceOutputRichText forceKnowledgeOutputRichTextForKnowledge"&gt;
&lt;UL data-aura-rendered-by="100161:0"&gt;
&lt;LI&gt;Cortex XDR for Windows&lt;/LI&gt;
&lt;LI&gt;Behavioral Threat Protection (BTP)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;答案：&lt;/P&gt;
&lt;P&gt;这不是一个假阳性检测。&lt;BR /&gt;这是一个易受攻击的驱动程序，正在被客户机器上的一个应用程序使用。所以我们阻止了它。&lt;BR /&gt;这个驱动程序可以被攻击者滥用，以获得权限的提升。&lt;BR /&gt;注意：如果一个规则名称有这些内容，它不是一个假阳性。它们也是由有漏洞的驱动文件引起的。&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="ckeditor_codeblock" data-aura-rendered-by="100190:0"&gt;&lt;SPAN&gt;bioc.vulnerable_driver_dropped_$name
bioc.sync.vulnerable_driver_loaded_$name
bioc.sync.vulnerable_driver_by_original_name_loaded_$name
bioc.sync.vulnerable_driver_by_signer_name_loaded_$name
bioc.sync.malicious_driver_by_signer_name_loaded_$name
bioc.sync.malicious_driver_by_original_name_loaded__$name&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 19 Jan 2023 11:53:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/%E9%85%8D%E7%BD%AE%E5%92%8C%E5%AE%9E%E6%96%BD/%E8%A7%84%E5%88%99%E5%90%8D%E7%A7%B0%E4%B8%BA-quot-bioc-vulnerable-driver-dropped-name-quot/ta-p/527697</guid>
      <dc:creator>juzhang</dc:creator>
      <dc:date>2023-01-19T11:53:03Z</dc:date>
    </item>
  </channel>
</rss>

