<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic cortex-xdr-payload.exe access lsass.exe in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cortex-xdr-payload-exe-access-lsass-exe/m-p/1225765#M2421</link>
    <description>&lt;P&gt;Hi guys,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I received an alert regarding &lt;CODE data-start="209" data-end="233"&gt;cortex-xdr-payload.exe&lt;/CODE&gt; accessing &lt;CODE data-start="244" data-end="255"&gt;lsass.exe&lt;/CODE&gt;. The full path is: below:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;C:\ProgramData\Cyvera\LocalSystem\Download\protected_payload_execution\cortex-xdr-payload.exe&lt;BR /&gt;&lt;BR /&gt;From my research, the legitimate &lt;CODE data-start="414" data-end="438"&gt;cortex-xdr-payload.exe&lt;/CODE&gt; is used for offline triage collection, but I haven’t found any references to other related functionalities.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="" data-start="381" data-end="407"&gt;I would like to confirm:&lt;/P&gt;
&lt;P class="" data-start="381" data-end="407"&gt;1. Is the file path valid?&lt;/P&gt;
&lt;P class="" data-start="381" data-end="407"&gt;2. Is this a legitimate process for checking &lt;CODE data-start="453" data-end="464"&gt;lsass.exe&lt;/CODE&gt;?&lt;/P&gt;
&lt;P class="" data-start="381" data-end="407"&gt;&lt;SPAN&gt;3. Is it possible to schedule this process? I noticed that the alert appears at the same time consistently.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="" data-start="608" data-end="643"&gt;Looking forward to your insights.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 05 Apr 2025 15:06:06 GMT</pubDate>
    <dc:creator>${userLoginName}</dc:creator>
    <dc:date>2025-04-05T15:06:06Z</dc:date>
    <item>
      <title>cortex-xdr-payload.exe access lsass.exe</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cortex-xdr-payload-exe-access-lsass-exe/m-p/1225765#M2421</link>
      <description>&lt;P&gt;Hi guys,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I received an alert regarding &lt;CODE data-start="209" data-end="233"&gt;cortex-xdr-payload.exe&lt;/CODE&gt; accessing &lt;CODE data-start="244" data-end="255"&gt;lsass.exe&lt;/CODE&gt;. The full path is: below:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;C:\ProgramData\Cyvera\LocalSystem\Download\protected_payload_execution\cortex-xdr-payload.exe&lt;BR /&gt;&lt;BR /&gt;From my research, the legitimate &lt;CODE data-start="414" data-end="438"&gt;cortex-xdr-payload.exe&lt;/CODE&gt; is used for offline triage collection, but I haven’t found any references to other related functionalities.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="" data-start="381" data-end="407"&gt;I would like to confirm:&lt;/P&gt;
&lt;P class="" data-start="381" data-end="407"&gt;1. Is the file path valid?&lt;/P&gt;
&lt;P class="" data-start="381" data-end="407"&gt;2. Is this a legitimate process for checking &lt;CODE data-start="453" data-end="464"&gt;lsass.exe&lt;/CODE&gt;?&lt;/P&gt;
&lt;P class="" data-start="381" data-end="407"&gt;&lt;SPAN&gt;3. Is it possible to schedule this process? I noticed that the alert appears at the same time consistently.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="" data-start="608" data-end="643"&gt;Looking forward to your insights.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Apr 2025 15:06:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cortex-xdr-payload-exe-access-lsass-exe/m-p/1225765#M2421</guid>
      <dc:creator>${userLoginName}</dc:creator>
      <dc:date>2025-04-05T15:06:06Z</dc:date>
    </item>
  </channel>
</rss>

