logo

Researchers Decrypt and Exploit Encrypted Palo Alto Cortex XDR BIOC Rules

ID: db0f53b9-e4cf-581f-b85d-c08e634fb534

STIX ID: report--db0f53b9-e4cf-581f-b85d-c08e634fb534

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-17

Date Updated: 2026-04-21

Author: Abinaya

...
...

InfoGuard Labs reverse-engineered Palo Alto Cortex XDR agent versions 8.7/8.8, decrypted the encrypted behavioral rule set, and found a hardcoded global allowlist that excludes processes whose command line contains "\\Windows\\ccmcache" from monitoring; this single exception bypassed roughly half of the platform's behavioral detections and was demonstrated to allow undetected LSASS dumping. The flaw was responsibly disclosed in July 2025 and patched by Palo Alto in February 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.