- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-10-2022 09:00 AM
Hello dear Community,
Does the Cortex XDR Agent work in Windows Safe Mode?
https://attack.mitre.org/techniques/T1562/009/
BR
Rob
08-11-2022 06:05 AM
Hi Rob,
The Cortex XDR Agent is currently not designed to function with Windows Safe Mode.
The following tests were performed on a Windows 10 endpoint that was booted into Windows Safe Mode with the Cortex XDR agent installed.
Figure 1: The tray application was not open upon the Safe Mode boot. After navigating to and running the tray executable file in C:\Project Files\ Palo Alto Networks\Traps, the menu displays that Advanced Endpoint Protection is disabled and that connection to the service is not available.
Figure 2: Cyserver.exe is the main process executable responsible for starting the Cortex XDR Service as of agent release 7.1 (see references for more information). After attempting to start the “cyserver” service from the command line with net start, there is a system error reading that “This service cannot be started in Safe Mode”.
Figure 3: Cytool is a command line interface tool that offers management with the components of Cortex XDR when operating in the directory C:\Project Files\ Palo Alto Networks\Traps. “cytool enum” enumerates protected processes (as seen in the cytool documentation listed below), but in this case the system cannot find the file specified to execute the command.
Since this test was done on a Windows 10 endpoint in particular, I would be interested to hear what Windows version you had in mind for the Windows Safe Mode Boot functionality.
Reference:
Cyserver.exe process details
Cytool functionality on Windows endpoints
08-11-2022 06:05 AM
Hi Rob,
The Cortex XDR Agent is currently not designed to function with Windows Safe Mode.
The following tests were performed on a Windows 10 endpoint that was booted into Windows Safe Mode with the Cortex XDR agent installed.
Figure 1: The tray application was not open upon the Safe Mode boot. After navigating to and running the tray executable file in C:\Project Files\ Palo Alto Networks\Traps, the menu displays that Advanced Endpoint Protection is disabled and that connection to the service is not available.
Figure 2: Cyserver.exe is the main process executable responsible for starting the Cortex XDR Service as of agent release 7.1 (see references for more information). After attempting to start the “cyserver” service from the command line with net start, there is a system error reading that “This service cannot be started in Safe Mode”.
Figure 3: Cytool is a command line interface tool that offers management with the components of Cortex XDR when operating in the directory C:\Project Files\ Palo Alto Networks\Traps. “cytool enum” enumerates protected processes (as seen in the cytool documentation listed below), but in this case the system cannot find the file specified to execute the command.
Since this test was done on a Windows 10 endpoint in particular, I would be interested to hear what Windows version you had in mind for the Windows Safe Mode Boot functionality.
Reference:
Cyserver.exe process details
Cytool functionality on Windows endpoints
08-11-2022 07:24 AM
Exactly this answers my question, thank you very much!
@PA: will there be a version which works in safe mode with networking?
08-11-2022 10:13 AM
Hi RFeyertag,
Please reach out to your SE/account team for discussions on product feedback and roadmap.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!