- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-19-2024 10:46 PM
Hello All,
Greetings for the day!
We are getting multiple high severity alerts/incidents related with excel files because of Behavioral threat detected (rule: excel_virus).
Within the time span of 4 hours we have received 28 high severity alerts in 12 different hostnames. Also, the high severity alert is getting generated for the newly created excel file in the system without any macro or function being used.
Please help to answer the below queries-
Regards,
Sakshi Seth
03-26-2024 01:12 AM
Hello @Seth_Sakshi ,
Thanks for reaching out on LiveCommunity!
To answer your question, Cortex XDR uses WF verdict and local analysis to provide the verdict of file.
You can go through below training to learn how to do IR and fine tune the alerts:
If you want to confirm the reputation, you can involve SE or submit the file to TAC to confirm the reputation.
Regards.
03-26-2024 03:38 AM
Hello @Seth_Sakshi
Thanks for reaching out on LiveCommunity!
This scenario require analysis of alert data to determine the root cause for alert. Hence please open a support case.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!