- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-14-2023 06:30 AM
“Behavior of hiding RWX code by modifying it to RX”
I've been seeing this alert that is considered high criticality and is blocking Windows updates.
Everything I can see says that this is benign.
XDR is saying that the Windows process is a non-whitelist CGO. I've verified that this is the legitimate Microsoft WerFault.exe
There is no description of what is triggering this alert, there is no description of this evasion technique, and the causality chain is very little help.
I've also verified that the behavior is caused when a user tries to update, or an automatic update starts.
Is anyone having a similar issue where XDR is blocking Windows updates?
11-20-2023 06:25 AM - edited 11-27-2023 11:47 AM
Started a support case and it was determined to be a false positive and will be fixed in the next content release (1190).
11-20-2023 06:25 AM - edited 11-27-2023 11:47 AM
Started a support case and it was determined to be a false positive and will be fixed in the next content release (1190).
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!