<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alerts: - Abnormal Recurring Communications to a Rare Domain to a Suspicious Autonomous System (AS) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/alerts-abnormal-recurring-communications-to-a-rare-domain-to-a/m-p/996616#M122392</link>
    <description>&lt;P&gt;Hello BPry&lt;/P&gt;
&lt;P&gt;Thank for your reply.&lt;/P&gt;
&lt;P&gt;Yes, the domain name is in the notifications. We checked endpoints browser, most alerts from google chrome and we find no any domain in alert has granted notification access and there is no extension installed on the browser.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Dec 2024 01:19:44 GMT</pubDate>
    <dc:creator>H.NguyenNgoc</dc:creator>
    <dc:date>2024-12-05T01:19:44Z</dc:date>
    <item>
      <title>Alerts: - Abnormal Recurring Communications to a Rare Domain to a Suspicious Autonomous System (AS)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alerts-abnormal-recurring-communications-to-a-rare-domain-to-a/m-p/995579#M122243</link>
      <description>&lt;P&gt;Hello Friends&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our XDR system recently reported a lot of these warnings, "Abnormal Recurring Communications to a Rare Domain to a Suspicious Autonomous System (AS)". Through information from XDR from the user's computer that has queried a website through Google Chrome or MS Edge. The investigation activity gets the user's access information that they have accessed and not accessed those website addresses.&lt;BR /&gt;This warning keeps appearing, so how to turn it off or how to find the exact cause of why this warning is there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2024 05:04:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alerts-abnormal-recurring-communications-to-a-rare-domain-to-a/m-p/995579#M122243</guid>
      <dc:creator>H.NguyenNgoc</dc:creator>
      <dc:date>2024-11-28T05:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts: - Abnormal Recurring Communications to a Rare Domain to a Suspicious Autonomous System (AS)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alerts-abnormal-recurring-communications-to-a-rare-domain-to-a/m-p/995746#M122267</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1651399447"&gt;@H.NguyenNgoc&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;XDR should be telling you the actual domain does it not? This would start usually as a pretty typical check of the endpoint; verify that the user doesn't have any malicious extensions added and remove any of the websites that they may have granted notification access to would be the first things that I would check.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2024 13:39:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alerts-abnormal-recurring-communications-to-a-rare-domain-to-a/m-p/995746#M122267</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-11-29T13:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts: - Abnormal Recurring Communications to a Rare Domain to a Suspicious Autonomous System (AS)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alerts-abnormal-recurring-communications-to-a-rare-domain-to-a/m-p/996616#M122392</link>
      <description>&lt;P&gt;Hello BPry&lt;/P&gt;
&lt;P&gt;Thank for your reply.&lt;/P&gt;
&lt;P&gt;Yes, the domain name is in the notifications. We checked endpoints browser, most alerts from google chrome and we find no any domain in alert has granted notification access and there is no extension installed on the browser.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 01:19:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alerts-abnormal-recurring-communications-to-a-rare-domain-to-a/m-p/996616#M122392</guid>
      <dc:creator>H.NguyenNgoc</dc:creator>
      <dc:date>2024-12-05T01:19:44Z</dc:date>
    </item>
  </channel>
</rss>

