How Cortex XDR BIOC Rules Could Become an Attack Surface
ID: 9d115ef4-1ef8-5aa2-a1b5-d6868c667faa
STIX ID: report--9d115ef4-1ef8-5aa2-a1b5-d6868c667faa
Feed Name: The Cyber Express
Threat Score
A study found that Cortex XDR BIOC detection rules—intended to be stored encrypted—can be decrypted and examined, exposing the internal detection logic. This disclosure could enable attackers to reverse-engineer and evade or manipulate endpoint detection, posing a risk across sectors that rely on EDR platforms, though the research does not report widespread active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
