False positives generated by alert Masquerading - 1396383840

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

False positives generated by alert Masquerading - 1396383840

L0 Member

Hi, 

 

Is anyone else experiencing lots of false positives for the BIOC - Masquerading - 1396383840, specifically relating to signed Microsoft system 32 files and Chrome?

 

The files initiating the alerts are all signed, have not been modified for a long time and I cannot see any malicious behaviour. 

3 REPLIES 3

L0 Member

yeah me too i dont know the cause

Hmm, I'm thinking this may be some misconfig on PaloAlto side. They had a similar incident a couple of months ago which created lots of alerts for TOR exit nodes which was also false positives. 

L0 Member

Hi,

 

We are also experiencing the same problem with Masquerading alerts.

It might trigger in certain conditions and it could be related to the latest CU 980 where they made some changes to BTP agent module.

  • 798 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!