How to remove this message: Microsoft Windows RPC Encrypted Data Detected from a windows 10 computer that palo alto always report this type of thread???
Whats mean Microsoft Windows RPC Encrypted Data Detected???
In addition to the explanation that Rodgerfoster provided above, I add some comments here.
This signature triggers when it sees encrypted MSRPC traffic, which can be used for evasion but also can be used legitimately. Thus, the severity is 'low' and the default action set to 'alert'.
Here's the description of the signature.
"This signature indicates that encrypted MSRPC data is seen. Though, encrypted traffic is sometimes used, it is also seen in cases of evasion. Attackers could use the technique to evade IPS boxes and thus sneak MSRPC exploits."
With this type of signature, I'd suggest to review the traffic (traffic log, etc) to see if it's known traffic. If you think that your traffic is legitimate, you can add a threat exception for this signature 33836.
HOW TO CREATE A VULNERABILITY EXCEPTION
WHAT IS THE BEHAVIOR WHEN IP ADDRESS/S ARE ADDED UNDER "IP-ADDRESS-EXEMPTIONS" FOR SPYWARE/THREAT EXCEPTION?
If you are unsure if the traffic is legitimate or not, you can collect some data and check with Palo Alto Networks support.
HOW TO SUBMIT A VULNERABILITY SIGNATURE FALSE POSITIVE
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!