07-29-2021 10:27 AM
This is messing up our EDR solution.
This program will run cmd.exe and then whoami /groups
C:\Program Files\Palo Alto Networks\GlobalProtect\PanGpHip.exe
Whoami as the Local System authority is a bad thing in our EDR world. Is there anyway to change this behaviour?