<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;SecureDriveService.dll&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/quot-securedriveservice-dll-quot/m-p/516660#M107292</link>
    <description>&lt;P&gt;Can you share the Wildfire report, or what characteristics that this hash is deplaying?&amp;nbsp; Recall that WF finds zero day sometimes day/hours/weeks before other vendors.&amp;nbsp; So the lack of info from the other vendors does not necessarily meeting that it is safe; only that they do not yet know what that hash is.&amp;nbsp;&amp;nbsp; You may want to research a little more. &lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Oct 2022 17:32:10 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2022-10-03T17:32:10Z</dc:date>
    <item>
      <title>"SecureDriveService.dll"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-securedriveservice-dll-quot/m-p/516608#M107284</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;While performing a malware analysis on Cortex XDR, Wildfire has detected a file on the computer as possible malware. The file has also been analyzed in other intelligence tools and has not been detected as malicious, the only tool that detects it as malware is Palo Alto Networks. It is the file "SecureDriveService.dll", with description PE32+ executable (DLL) (GUI) x86-64, for MS Windows, with SHA256: e69a1b28a5b71549177f09a9ef7a336831400479ce6f3c6856bc8a818170745d.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please , could you give us some feedback and indicate if it can be treated as false positive?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT&gt;BR&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 10:30:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-securedriveservice-dll-quot/m-p/516608#M107284</guid>
      <dc:creator>jesusyas</dc:creator>
      <dc:date>2022-10-03T10:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: "SecureDriveService.dll"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-securedriveservice-dll-quot/m-p/516660#M107292</link>
      <description>&lt;P&gt;Can you share the Wildfire report, or what characteristics that this hash is deplaying?&amp;nbsp; Recall that WF finds zero day sometimes day/hours/weeks before other vendors.&amp;nbsp; So the lack of info from the other vendors does not necessarily meeting that it is safe; only that they do not yet know what that hash is.&amp;nbsp;&amp;nbsp; You may want to research a little more. &lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 17:32:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-securedriveservice-dll-quot/m-p/516660#M107292</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2022-10-03T17:32:10Z</dc:date>
    </item>
  </channel>
</rss>

