<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Endpoint connector 7.5.3.20938 flagging every service start as IOC in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/endpoint-connector-7-5-3-20938-flagging-every-service-start-as/m-p/4585546#M6788</link>
    <description>&lt;P&gt;Just about every service start command is being flagged as an IOC right now. I've gotten around 30 or 40 alerts in the last hour for normal service starting behavior, some examples:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;C:\Windows\system32\svchost.exe -k localService -p -s RemoteRegistry&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;C:\Windows\System32\svchost.exe -k NetSvcs -p -s NcaSvc&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s NgcSvc&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;C:\Windows\system32\svchost.exe -k netsvcs -p -s wuauserv&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All these are getting flagged:&amp;nbsp;Cloud IOC: ExecutedMalware.ioc&lt;/P&gt;&lt;P&gt;These are all normal service startup commands.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Apr 2022 19:54:19 GMT</pubDate>
    <dc:creator>davalosn</dc:creator>
    <dc:date>2022-04-04T19:54:19Z</dc:date>
    <item>
      <title>Endpoint connector 7.5.3.20938 flagging every service start as IOC</title>
      <link>https://community.cisco.com/t5/endpoint-security/endpoint-connector-7-5-3-20938-flagging-every-service-start-as/m-p/4585546#M6788</link>
      <description>&lt;P&gt;Just about every service start command is being flagged as an IOC right now. I've gotten around 30 or 40 alerts in the last hour for normal service starting behavior, some examples:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;C:\Windows\system32\svchost.exe -k localService -p -s RemoteRegistry&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;C:\Windows\System32\svchost.exe -k NetSvcs -p -s NcaSvc&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s NgcSvc&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;C:\Windows\system32\svchost.exe -k netsvcs -p -s wuauserv&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All these are getting flagged:&amp;nbsp;Cloud IOC: ExecutedMalware.ioc&lt;/P&gt;&lt;P&gt;These are all normal service startup commands.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 19:54:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/endpoint-connector-7-5-3-20938-flagging-every-service-start-as/m-p/4585546#M6788</guid>
      <dc:creator>davalosn</dc:creator>
      <dc:date>2022-04-04T19:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint connector 7.5.3.20938 flagging every service start as IOC</title>
      <link>https://community.cisco.com/t5/endpoint-security/endpoint-connector-7-5-3-20938-flagging-every-service-start-as/m-p/4585587#M6798</link>
      <description>&lt;P&gt;All FPs.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check your Announcements panel in the console.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 21:41:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/endpoint-connector-7-5-3-20938-flagging-every-service-start-as/m-p/4585587#M6798</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2022-04-04T21:41:54Z</dc:date>
    </item>
  </channel>
</rss>

