Cortex xdr did not detect malware, what good is it?

Reply
Highlighted
L1 Bithead

Cortex xdr did not detect malware, what good is it?

Cortex XDR did not detect malware, what good is it?

I got this scan with mal warebytes.  41 detected.

 

SimonTan_0-1595020002980.jpeg

 

 

Highlighted
L4 Transporter

Hi @SimonTan-

 

Just curious, did you try to run these binaries or leverage a scan.  What enforcement did you specify in your profiles / policy rules?  On the malware side there are several checks:

WildFire

  • WF Static Analysis
  • Machine Learning
  • Dynamic Analysis
  • Bare Metal

for unknown, the local analysis should do the examination at the point of execution.

 

In addition to the malware prevention, Cortex XDR includes behavior threat protection, anti-ransomware, password theft protection, child process protection, and approximately 30 ways to exploitation.

 

If you are using a scan for dormant malware, it is not the same as having all of the different protection levels that are leveraged during point of execution.  Are you able to share any hash / artifact info for verification?

 

 


David Falcon 
MDR Systems Engineer, Cortex
Palo AltoNetworks® 
Highlighted
L4 Transporter

Hi @SimonTan-

 

I would actually be happy to set up a Zoom with you to look over your configuration.  Based on your screenshot from MB, I believe that you may not have Cortex XDR configured to your needs.  For instance, in your screenshot, I see a large number of Potentially Unwanted Applications.  These are not malware.  Cortex XDR can be configured to treat these the same as malware.  On the malware side, I'd be very interested in checking into these as well.  

 

Please let me know if you would like to set up a session.  


David Falcon 
MDR Systems Engineer, Cortex
Palo AltoNetworks® 
Highlighted
L1 Bithead

how to retrieve a support file  and malware scan log?

SimonTan_0-1595351803583.png

 

Highlighted
L4 Transporter

Right click on that entry and select Additional Data.

dfalcon_0-1595359444215.png

Once in the details screen, right click on the entry in the list to download the TSF.

 

dfalcon_1-1595359535378.png

 

 

 


David Falcon 
MDR Systems Engineer, Cortex
Palo AltoNetworks® 
Highlighted
L4 Transporter

On the malware scan log.  Same thing.  Right click on the entry within the All Actions interface and select additional data.

 

From there, locate the entry, right-click and select View Related Alerts.

 

dfalcon_0-1595359693953.png

 


David Falcon 
MDR Systems Engineer, Cortex
Palo AltoNetworks® 
Highlighted
L1 Bithead

got it, send file to the tech and see what they say.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!