<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Cortex XDR]]></title><description><![CDATA[<p>Cortex XDR</p><p>Alert Name: Abnormal Recurring Communications to a Rare Domain With a Less Common Port<br />Alert id: --- <br />Severity: Low <br />Source: XDR Analytics BIOC <br />Category: Command and Control <br />Action: Detected <br />Description: The host [$host] was seen communicating to the external entity [$domain]. Communication between these entities was seen 13 times. This external entity is rare in the organization as only 4 hosts within the organization accessed it. This external entity is also rare globally. This external entity was accessed using 1 distinct ports. Based on our machine learning models, this connection was flagged as suspicious</p><p>hint, it was SSH.</p>]]></description><link>https://board.circlewithadot.net/topic/8e94861d-c2e9-481c-85ec-579bc4f9688f/cortex-xdr</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 06:53:07 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/8e94861d-c2e9-481c-85ec-579bc4f9688f.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 24 Apr 2026 20:16:06 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Cortex XDR on Sat, 25 Apr 2026 17:41:09 GMT]]></title><description><![CDATA[<p><span><a href="/user/cybeej%40infosec.exchange">@<span>cybeej</span></a></span> it is when our whole org uses SSH and these alerts trigger every 30 days to known and internal DNS </p><p>We have attempted to exclude these from alerting, but Cortex keeps finding new, exciting, and vague ways to continue to throw alerts.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/kajer/statuses/116466572982885758</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/kajer/statuses/116466572982885758</guid><dc:creator><![CDATA[kajer@infosec.exchange]]></dc:creator><pubDate>Sat, 25 Apr 2026 17:41:09 GMT</pubDate></item><item><title><![CDATA[Reply to Cortex XDR on Sat, 25 Apr 2026 04:27:45 GMT]]></title><description><![CDATA[<p><span><a href="/user/kajer%40infosec.exchange">@<span>kajer</span></a></span> tbf that’s not an unreasonable reason to trigger an alert is it?</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/cybeej/statuses/116463453192766697</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/cybeej/statuses/116463453192766697</guid><dc:creator><![CDATA[cybeej@infosec.exchange]]></dc:creator><pubDate>Sat, 25 Apr 2026 04:27:45 GMT</pubDate></item></channel></rss>