Researchers Uncover Ways to Decrypt Palo Alto Cortex XDR BIOC Rules for Evasion
ID: 339bc4ad-1113-5180-98c1-d59f8da6a04c
STIX ID: report--339bc4ad-1113-5180-98c1-d59f8da6a04c
Feed Name: GBHackers
Threat Score
Researchers disclosed that Cortex XDR Windows agents (v8.7/8.8) used an AES-256-CBC protected but reproducibly decryptable rule store; by extracting plaintext BIOC rules they found a hardcoded global whitelist which allowed attackers to bypass behavioral detections by appending a string like ":\Windows\ccmcache" to command-line arguments (e.g., using procdump to dump LSASS) — Palo Alto patched the issue in Feb 2026 and recommends upgrading to Agent 9.1 and content version 2160+.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
