Behavioral threat detected (rule: bioc.sync.critical_termination) Triggered By Known Good Files

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Behavioral threat detected (rule: bioc.sync.critical_termination) Triggered By Known Good Files

L1 Bithead

Over the past two weeks we have been seeing detections/blocks from the following rule "Behavioral threat detected (rule: bioc.sync.critical_termination)" for known good files 7z2301-x64.exe (7-zip install) and PhotosService.exe (part of built-in Windows Photos app).  We only see the detections on a few systems, many systems have these same files without any detections.  VirusTotal shows both files as clean and WildFire indicates they are benign.  What is causing these detections to keep recurring for Behavioral threat detected (rule: bioc.sync.critical_termination) for these files only on certain systems?

 

We have a case open since early last week but have not made any progress on this issue so I thought I would post here.

3 REPLIES 3

L2 Linker

While the case is analyzed and If it's a false positive then you can right click on the alert and add alert exception.. select the files based on which you want to add exception. 

 

This would make sure that alert is not triggered again on those files by that specific rule.

 

You can later review your exception based on the case feedback 

Hi, I've added an alert exception for the detected file (PhotosService.exe) but Behavioral threat detected (rule: bioc.sync.critical_termination) is still being triggered when I try to launch the Photos app.

Hi jdbst56

You can right click on the alert and go to: manage alert option-> exclude alert.

The agent continues to raise excluded alerts on the endpoint, but they are not saved or displayed in Cortex XDR.

More information about exclusion: https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Alert-Exclu...

SmartIT
  • 524 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!