Does the Cortex XDR Agent work in Windows Safe Mode?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Does the Cortex XDR Agent work in Windows Safe Mode?

L4 Transporter

Hello dear Community, 

 

Does the Cortex XDR Agent work in Windows Safe Mode?

 

https://attack.mitre.org/techniques/T1562/009/

RFeyertag_0-1660147159121.png

 

BR

 

Rob

 

1 accepted solution

Accepted Solutions

L3 Networker

Hi Rob,

 

The Cortex XDR Agent is currently not designed to function with Windows Safe Mode.

 

The following tests were performed on a Windows 10 endpoint that was booted into Windows Safe Mode with the Cortex XDR agent installed.

 

mfakhouri_0-1660222902982.png

Figure 1: The tray application was not open upon the Safe Mode boot. After navigating to and running the tray executable file in C:\Project Files\ Palo Alto Networks\Traps, the menu displays that Advanced Endpoint Protection is disabled and that connection to the service is not available.

 

mfakhouri_1-1660222902986.png

Figure 2: Cyserver.exe is the main process executable responsible for starting the Cortex XDR Service as of agent release 7.1 (see references for more information). After attempting to start the “cyserver” service from the command line with net start, there is a system error reading that “This service cannot be started in Safe Mode”.

 

mfakhouri_2-1660222902944.png

Figure 3: Cytool is a command line interface tool that offers management with the components of Cortex XDR when operating in the directory C:\Project Files\ Palo Alto Networks\Traps. “cytool enum” enumerates protected processes (as seen in the cytool documentation listed below), but in this case the system cannot find the file specified to execute the command.

 

Since this test was done on a Windows 10 endpoint in particular, I would be interested to hear what Windows version you had in mind for the Windows Safe Mode Boot functionality. 

 

Reference:

 

Cyserver.exe process details

https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-1/cortex-xdr-agent-release-notes/cortex-xdr-ag...

 

Cytool functionality on Windows endpoints

https://docs.paloaltonetworks.com/cortex/cortex-xdr/5-0/cortex-xdr-agent-admin/traps-agent-for-windo...

View solution in original post

3 REPLIES 3

L3 Networker

Hi Rob,

 

The Cortex XDR Agent is currently not designed to function with Windows Safe Mode.

 

The following tests were performed on a Windows 10 endpoint that was booted into Windows Safe Mode with the Cortex XDR agent installed.

 

mfakhouri_0-1660222902982.png

Figure 1: The tray application was not open upon the Safe Mode boot. After navigating to and running the tray executable file in C:\Project Files\ Palo Alto Networks\Traps, the menu displays that Advanced Endpoint Protection is disabled and that connection to the service is not available.

 

mfakhouri_1-1660222902986.png

Figure 2: Cyserver.exe is the main process executable responsible for starting the Cortex XDR Service as of agent release 7.1 (see references for more information). After attempting to start the “cyserver” service from the command line with net start, there is a system error reading that “This service cannot be started in Safe Mode”.

 

mfakhouri_2-1660222902944.png

Figure 3: Cytool is a command line interface tool that offers management with the components of Cortex XDR when operating in the directory C:\Project Files\ Palo Alto Networks\Traps. “cytool enum” enumerates protected processes (as seen in the cytool documentation listed below), but in this case the system cannot find the file specified to execute the command.

 

Since this test was done on a Windows 10 endpoint in particular, I would be interested to hear what Windows version you had in mind for the Windows Safe Mode Boot functionality. 

 

Reference:

 

Cyserver.exe process details

https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-1/cortex-xdr-agent-release-notes/cortex-xdr-ag...

 

Cytool functionality on Windows endpoints

https://docs.paloaltonetworks.com/cortex/cortex-xdr/5-0/cortex-xdr-agent-admin/traps-agent-for-windo...

Exactly this answers my question, thank you very much! 

@PA: will there be a version which works in safe mode with networking?

Hi RFeyertag,

 

Please reach out to your SE/account team for discussions on product feedback and roadmap.

  • 1 accepted solution
  • 2475 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!