Cortex XDR has Blocked a Malicious Activity but No Program Listed

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Cortex XDR has Blocked a Malicious Activity but No Program Listed

L0 Member

Attached images show the pop-up that is going around our network this morning.  Unlike before where it would list the program Cortex blocks there is nothing there and is pointing at Microsoft for the cause.

 

Is this a false positive?  A windows service is triggering Cortex to block the behavioral threat?

20 REPLIES 20

L0 Member

We're getting the same type alert this morning on all our endpoints.  We haven't determined what is causing it though.

L2 Linker

We are seeing Cortex Behavioral Threat High Blocks related to Microsoft.  Pretty much all end points.   smss.exe .. a MSFT signed file is identified.   Unclear what is the precise cause. 

L0 Member

Minor update my home office PC (Windows 100 Pro) now got the notification from XDR while at work we use Windows 10 Pro.  Can never have a quiet day off can I?  😛

L3 Networker

Hi,

We're seeing the same here as well. End users are shown no application name, but digging through the incidents in the console shows that it's killing of Smss.exe, which is the System Center Configuration Manager agent.

All endpoints generating alerts are running 7.7.0.60725 here.

Looking through the timeline there seems to be no evidence of foul play.

L2 Linker

We are on 7.7.0 as well.

 

Thanks for the comment

L3 Networker

This alert just trigged on my personal device when updating to content version 500-90199.
Sooo... rollback, please?

L2 Linker

We have a Support ticket opened (High Severity) and also are working with an inside (Palo) engineer associated with our Sales team.  So hopefully we will learn more soon.

 

L3 Networker

@KMcKenna Please let us know if they provide a workaround or a fix for the issue.

Fingers crossed the update either get fixed or pulled tonight, so I won't have to deal with this when each endpoint boots tomorrow.

L2 Linker

Yes, absolutely.

 

For reference, if anyone else opens a case, our Case # is 02191931.

 

The rule triggering the alert is: 

 

Behavioral threat detected (rule: other.malware_gen_task.105)

L1 Bithead

Getting this too. It occurs after the latest content & policy update. I can manually trigger it but clicking check-in now button, so its like the process that applies the policy update is triggering itself lol.

 

You can verify this in the endpoint log on portal, it triggers same time as the policy

update. 

 

Support case logged also: 

CASE #: 02191983

 

XDR event timestamps.png

Policy Update Timestamps.png

  

 

L2 Linker

@adminBandE   I also clicked Check In Now on a completely isolated host (off site).   Had same response as you in that the Alert triggered.

 

Will add that to our support case.  Thanks

Update from my Case:

From the case description, I understand that you are receiving BTP alerts for smss.exe for the rule other.malware_gen_task.105
I would like to inform you that it is a false positive BTP alert and multiple customers where reported the same. We are working on the fix and will update you as soon as available.
As a workaround please create an alert exception for now reference.

 

I just created the (temporary) exception, lets see if it takes effect!

 

Edit: It does work. Apply the alert exception from the incident under alerts & insights, right-click the alert and select manage alert - create alert exception.  It will then appear under your global BTP rules. 

L0 Member

Hoping for all of us as user calls about will get very old very fast.

L2 Linker

We are being told this is a False Positive and the Palo Support team is working on it.   They say to create an exclusion in the meantime.  Some general info on doing that...

https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/exception...

 

This is a general Docs page.  So if you are not familiar with doing this, you may need more info.   This is linked info not specific to this alert.

 

That's all I have at the moment.

 

  • 18636 Views
  • 20 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!