<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sdbinst.exe Cloud IOC and Command Line Arguments in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4650316#M6979</link>
    <description>&lt;P&gt;I see a few alerts every day, only on PC's with Windows 11 Version 22H2, (OS Build 22621.169) so I think we can confirm that it is due to the most recent Windows patches.&amp;nbsp; I am checking other Win 11 PC's that havent been patched fully and I dont even see SDBinst.exe running on these machines.&amp;nbsp; I am able to silence the Compromise Event Type &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;"W32.SdbinstShimming.ioc"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; and then they all are hidden, I just havent had to silence an event type before and would much prefer figuring out what is causing these.&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jul 2022 14:08:56 GMT</pubDate>
    <dc:creator>wwebster3</dc:creator>
    <dc:date>2022-07-14T14:08:56Z</dc:date>
    <item>
      <title>Sdbinst.exe Cloud IOC and Command Line Arguments</title>
      <link>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4642503#M6939</link>
      <description>&lt;P&gt;AMP has been generating a Cloud IOC alert for the following command line:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;C:\WINDOWS\System32\sdbinst.exe -m -bg&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't find anything for these arguments "-m -bg".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone come across this or know what it means?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2022 15:32:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4642503#M6939</guid>
      <dc:creator>JuliaMora15110</dc:creator>
      <dc:date>2022-07-01T15:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: Sdbinst.exe Cloud IOC and Command Line Arguments</title>
      <link>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4642529#M6940</link>
      <description>&lt;P&gt;I've been seeing it myself on my own PC after upgrading to Windows 11. I tried and failed to exclude it from my policy in the Secure Endpoint console. Windows Defender and VirusTotal report the file is fine.&lt;/P&gt;
&lt;P&gt;I will open a ticket on it eventually but haven't had the time to engage TAC.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2022 16:38:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4642529#M6940</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-07-01T16:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: Sdbinst.exe Cloud IOC and Command Line Arguments</title>
      <link>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4644838#M6944</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1108227"&gt;@JuliaMora15110&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;to get any community help in such a case we need more information, more details. There are millions of different command line arguments, and millions of relations to other observables, which finally may generate an event of CloudIOC. I did a short test in my LAB.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The Severity Level of the IOC is Medium. This means, take a look if there is anything else on the system active.&lt;/LI&gt;
&lt;LI&gt;Would be interesting if there are any other unknown files shown on the system&lt;/LI&gt;
&lt;LI&gt;Or, if there are any other Events&lt;/LI&gt;
&lt;LI&gt;Would be interesting which user did the command&lt;/LI&gt;
&lt;LI&gt;The outlined tool can be used to do malicious activity, but this command provides not the necessary threat details to determine if there is really something malicious happening on the endpoint. Th tool is also listed on Mitre:&amp;nbsp;&lt;A href="https://attack.mitre.org/techniques/T1546/011/" target="_blank" rel="noopener"&gt;https://attack.mitre.org/techniques/T1546/011/&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;So finally, you may take a closer look on the endpoint if you figure out any other activity.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Greetings,&lt;BR /&gt;Thorsten&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Bildschirmfoto 2022-07-06 um 09.50.09.png" style="width: 1008px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/155236i6DB42A8048C7B7FB/image-dimensions/1008x267?v=v2" width="1008" height="267" role="button" title="Bildschirmfoto 2022-07-06 um 09.50.09.png" alt="Bildschirmfoto 2022-07-06 um 09.50.09.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 08:14:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4644838#M6944</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2022-07-06T08:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: Sdbinst.exe Cloud IOC and Command Line Arguments</title>
      <link>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4645196#M6945</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/547768"&gt;@Troja007&lt;/a&gt; can you tell us how to exclude this file from generating Cloud IOC events? I've scanned it with different tools and it comes up clean in every case. I tried whitelisting the file hash in my policy but that had no effect.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 17:11:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4645196#M6945</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-07-06T17:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: Sdbinst.exe Cloud IOC and Command Line Arguments</title>
      <link>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4645303#M6946</link>
      <description>You can only silence the alarm, the event still happens.  Click on the bell in the alarm to silence it.&lt;BR /&gt;To remove the event TAC or Dev have to get involved...&lt;BR /&gt;</description>
      <pubDate>Wed, 06 Jul 2022 18:24:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4645303#M6946</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2022-07-06T18:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: Sdbinst.exe Cloud IOC and Command Line Arguments</title>
      <link>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4645610#M6947</link>
      <description>&lt;P&gt;Hello all,&lt;BR /&gt;as&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/321979"&gt;@Ken Stieers&lt;/a&gt;&amp;nbsp;already mentioned, what you can do &lt;STRONG&gt;today&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Option 1: Silence the Alarm&lt;/LI&gt;
&lt;LI&gt;Option 1: open a TAC case, so there is an exclusion added to your ORG in the backend&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In addition, we are already working on a new feature to enable customers defining their own CloudIOC exclusions. &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1108227"&gt;@JuliaMora15110&lt;/a&gt;&amp;nbsp;, you may get in contact with your Cisco representative for any official statement.&lt;/P&gt;
&lt;P&gt;Greetings,&lt;BR /&gt;Thorsten&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2022 07:29:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4645610#M6947</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2022-07-07T07:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: Sdbinst.exe Cloud IOC and Command Line Arguments</title>
      <link>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4645951#M6949</link>
      <description>&lt;P&gt;Thank you, I've opened a Cisco TAC case and provided the debugging logs. I just want to know if this has been seen before and if it's expected behavior for Windows 11. If so, I'm hoping that the Cloud IOC can be fine tuned.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2022 14:15:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4645951#M6949</guid>
      <dc:creator>JuliaMora15110</dc:creator>
      <dc:date>2022-07-07T14:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Sdbinst.exe Cloud IOC and Command Line Arguments</title>
      <link>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4648817#M6962</link>
      <description>&lt;P&gt;I am now seeing this alert come from all computers that have been updated to the latest &lt;SPAN&gt;Windows 11 build 22621.105&lt;/SPAN&gt;.&lt;BR /&gt;&lt;BR /&gt;One of the alerts had a sdbinst.exe -mm parameter but that also is undefined.&lt;/P&gt;&lt;P&gt;I can't find anything about this behavior online besides this thread which is unfortunate. I have checked the machines throwing up these alerts for custom Shim DB's but there weren't any in the regular folder locations.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 15:02:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4648817#M6962</guid>
      <dc:creator>wwebster3</dc:creator>
      <dc:date>2022-07-12T15:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: Sdbinst.exe Cloud IOC and Command Line Arguments</title>
      <link>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4648935#M6963</link>
      <description>&lt;P&gt;Is this a Lenovo computer? What is the Make Model and Windows Version of the machines you are seeing this on?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 17:39:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4648935#M6963</guid>
      <dc:creator>wwebster3</dc:creator>
      <dc:date>2022-07-12T17:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Sdbinst.exe Cloud IOC and Command Line Arguments</title>
      <link>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4648940#M6964</link>
      <description>&lt;P&gt;I see it consistently (every couple of days) on my HP Spectre x360 computer with Windows 11 Version 22H2, (OS Build 22621.169). It's fully patched and no other tool indicates this file is a problem. Silencing the alarm only silences that particular instance and it recurs eventually.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 17:52:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4648940#M6964</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-07-12T17:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: Sdbinst.exe Cloud IOC and Command Line Arguments</title>
      <link>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4650316#M6979</link>
      <description>&lt;P&gt;I see a few alerts every day, only on PC's with Windows 11 Version 22H2, (OS Build 22621.169) so I think we can confirm that it is due to the most recent Windows patches.&amp;nbsp; I am checking other Win 11 PC's that havent been patched fully and I dont even see SDBinst.exe running on these machines.&amp;nbsp; I am able to silence the Compromise Event Type &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;"W32.SdbinstShimming.ioc"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; and then they all are hidden, I just havent had to silence an event type before and would much prefer figuring out what is causing these.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 14:08:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4650316#M6979</guid>
      <dc:creator>wwebster3</dc:creator>
      <dc:date>2022-07-14T14:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: Sdbinst.exe Cloud IOC and Command Line Arguments</title>
      <link>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4650361#M6980</link>
      <description>&lt;P&gt;I just confirmed that something must have changed at least between Win 10 and Win 11. In the screen shot you can see the variables "-mm" and "-m -bg" execute without error in Windows 11 Version 22H2, (OS Build 22621.169), but they error out in Windows 10.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 14:46:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4650361#M6980</guid>
      <dc:creator>wwebster3</dc:creator>
      <dc:date>2022-07-14T14:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Sdbinst.exe Cloud IOC and Command Line Arguments</title>
      <link>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4663196#M7024</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I received a reply from Cisco TAC regarding this detection - a fix has been applied to the backend and should no longer display as a Cloud IOC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much for confirming this was due to Windows 11 update!&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 19:54:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4663196#M7024</guid>
      <dc:creator>JuliaMora15110</dc:creator>
      <dc:date>2022-08-03T19:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Sdbinst.exe Cloud IOC and Command Line Arguments</title>
      <link>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4663688#M7025</link>
      <description>&lt;P&gt;Thank you Julia,&amp;nbsp; Can confirm the alerts have stopped.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 13:29:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/sdbinst-exe-cloud-ioc-and-command-line-arguments/m-p/4663688#M7025</guid>
      <dc:creator>wwebster3</dc:creator>
      <dc:date>2022-08-04T13:29:50Z</dc:date>
    </item>
  </channel>
</rss>

