Cortex XDR Prevent Did Not Detect ncat

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cortex XDR Prevent Did Not Detect ncat

L1 Bithead

Hello I am new to Cortex XDR. I tried ncat on a PC with Cortex XDR Prevent (with Windows Defender) and it did not detect or stop the connection from Kali a PC. Windows Defender showed a warning and once I allowed it I was able to connect on ncat from Kali. Is Cortex XDR Prevent supposed to stop ncat or at least give me an email alert about the connection? Anybody else tried this and with the same result? I will try this with Symantec and will see if Symantec stops the ncat connection. 

 

Thank you 

 

8 REPLIES 8

L2 Linker

Consider two things:

 

1. Windows Defender should be disabled on PC that runs Cortex XDR. If this does not occur automatically, disable it manually as it could intervene with Cortex XDR.

 

2. In case Cortex XDR does not indeed prevent it by default, you can always create a BIOC rule to detect NCAT and then set it as prevention rule inside the Restrictions Profile -> Custom Prevention Rules.

 

Best,

David

@DKasabji, I am seeing some devices where Windows Defender Antivirus still have the service running.  I disable it via GPO and surprised to see it running on my system.  With the new tamper protections I have yet to figure out how to disable the service so it is like it is "off" but still running the app behind the scenes.  We are not Intune subscribers so there does not appear to be a way to turn it off if Cortex fails to do so.

L2 Linker

@tech_noob, doesn't ncat have legtimate uses so in and of itself it is not evil?  Do you have the grayware protection enabled? (Just thinking out loud...I am not experienced with Kali or ncat.

@EddieRowe Aren't you able to disable Tamper protection on Windows? That way you can disable Defender via GPO. 

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!