Cortex XDR has Blocked a Malicious Activity but No Program Listed

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cortex XDR has Blocked a Malicious Activity but No Program Listed

L0 Member

Attached images show the pop-up that is going around our network this morning.  Unlike before where it would list the program Cortex blocks there is nothing there and is pointing at Microsoft for the cause.


Is this a false positive?  A windows service is triggering Cortex to block the behavioral threat?


L0 Member

We're getting the same type alert this morning on all our endpoints.  We haven't determined what is causing it though.

L2 Linker

We are seeing Cortex Behavioral Threat High Blocks related to Microsoft.  Pretty much all end points.   smss.exe .. a MSFT signed file is identified.   Unclear what is the precise cause. 

L0 Member

Minor update my home office PC (Windows 100 Pro) now got the notification from XDR while at work we use Windows 10 Pro.  Can never have a quiet day off can I?  😛

L3 Networker


We're seeing the same here as well. End users are shown no application name, but digging through the incidents in the console shows that it's killing of Smss.exe, which is the System Center Configuration Manager agent.

All endpoints generating alerts are running here.

Looking through the timeline there seems to be no evidence of foul play.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!