logo

Researchers Uncover Ways to Decrypt Palo Alto Cortex XDR BIOC Rules for Evasion

ID: 339bc4ad-1113-5180-98c1-d59f8da6a04c

STIX ID: report--339bc4ad-1113-5180-98c1-d59f8da6a04c

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-17

Date Updated: 2026-04-22

Author: Divya

...
...

Researchers disclosed that Cortex XDR Windows agents (v8.7/8.8) used an AES-256-CBC protected but reproducibly decryptable rule store; by extracting plaintext BIOC rules they found a hardcoded global whitelist which allowed attackers to bypass behavioral detections by appending a string like ":\Windows\ccmcache" to command-line arguments (e.g., using procdump to dump LSASS) — Palo Alto patched the issue in Feb 2026 and recommends upgrading to Agent 9.1 and content version 2160+.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.