Researchers Decrypt and Exploit Encrypted Palo Alto Cortex XDR BIOC Rules
ID: db0f53b9-e4cf-581f-b85d-c08e634fb534
STIX ID: report--db0f53b9-e4cf-581f-b85d-c08e634fb534
Feed Name: cybersecurityNews.com
InfoGuard Labs reverse-engineered Palo Alto Cortex XDR agent versions 8.7/8.8, decrypted the encrypted behavioral rule set, and found a hardcoded global allowlist that excludes processes whose command line contains "\\Windows\\ccmcache" from monitoring; this single exception bypassed roughly half of the platform's behavioral detections and was demonstrated to allow undetected LSASS dumping. The flaw was responsibly disclosed in July 2025 and patched by Palo Alto in February 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
