<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Retrospective Detections for DevHome files in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5116709#M8363</link>
    <description>&lt;P&gt;Anybody else getting retrospective detections for these files?&amp;nbsp; They are created by legitimate&amp;nbsp;svchost.exe&lt;/P&gt;&lt;P&gt;Looks like they must be components of Dev Home&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/dev-home/" target="_blank"&gt;Dev Home for Windows Developers | Microsoft Learn&lt;/A&gt;&lt;/P&gt;&lt;P&gt;DevHome.RegistryPreview.exe&lt;BR /&gt;47f2ecbbc1f812b63042c8b0a1132956e8fd3ebad3296b8fd4e65f89d5b1cdd5&lt;/P&gt;&lt;P&gt;File full path:&amp;nbsp;&lt;/P&gt;&lt;P&gt;c:\program files\windowsapps\microsoft.windows.devhome_0.1401.505.0_x64__8wekyb3d8bbwe\devhome.registrypreview.exe&lt;/P&gt;&lt;P&gt;DevHome.EnvironmentVariables.exe&lt;BR /&gt;c22d299aadceb1c008c1feeb2a94ec9d7c9af537f21506fbc6dde91107a2ae20&lt;/P&gt;&lt;P&gt;File full path:&amp;nbsp;c:\program files\windowsapps\microsoft.windows.devhome_0.1401.505.0_x64__8wekyb3d8bbwe\devhome.environmentvariables.exe&lt;/P&gt;</description>
    <pubDate>Sat, 25 May 2024 21:16:11 GMT</pubDate>
    <dc:creator>ARB65</dc:creator>
    <dc:date>2024-05-25T21:16:11Z</dc:date>
    <item>
      <title>Retrospective Detections for DevHome files</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5116709#M8363</link>
      <description>&lt;P&gt;Anybody else getting retrospective detections for these files?&amp;nbsp; They are created by legitimate&amp;nbsp;svchost.exe&lt;/P&gt;&lt;P&gt;Looks like they must be components of Dev Home&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/dev-home/" target="_blank"&gt;Dev Home for Windows Developers | Microsoft Learn&lt;/A&gt;&lt;/P&gt;&lt;P&gt;DevHome.RegistryPreview.exe&lt;BR /&gt;47f2ecbbc1f812b63042c8b0a1132956e8fd3ebad3296b8fd4e65f89d5b1cdd5&lt;/P&gt;&lt;P&gt;File full path:&amp;nbsp;&lt;/P&gt;&lt;P&gt;c:\program files\windowsapps\microsoft.windows.devhome_0.1401.505.0_x64__8wekyb3d8bbwe\devhome.registrypreview.exe&lt;/P&gt;&lt;P&gt;DevHome.EnvironmentVariables.exe&lt;BR /&gt;c22d299aadceb1c008c1feeb2a94ec9d7c9af537f21506fbc6dde91107a2ae20&lt;/P&gt;&lt;P&gt;File full path:&amp;nbsp;c:\program files\windowsapps\microsoft.windows.devhome_0.1401.505.0_x64__8wekyb3d8bbwe\devhome.environmentvariables.exe&lt;/P&gt;</description>
      <pubDate>Sat, 25 May 2024 21:16:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5116709#M8363</guid>
      <dc:creator>ARB65</dc:creator>
      <dc:date>2024-05-25T21:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: Retrospective Detections for DevHome files</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5116711#M8364</link>
      <description>I am not currently, but my dev guys may not have it..&lt;BR /&gt;&lt;BR /&gt;For a quick fix you can set these file to allowed.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Submit the Sha256 for each file to Talosintelligence.com so they can figure out what is marking them and possibly fix it.&lt;BR /&gt;</description>
      <pubDate>Sat, 25 May 2024 21:31:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5116711#M8364</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2024-05-25T21:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: Retrospective Detections for DevHome files</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5116713#M8365</link>
      <description>I did but I got an automated close response saying they'd already been submitted.&lt;BR /&gt;&lt;BR /&gt;I opened the TAC case&lt;BR /&gt;</description>
      <pubDate>Sat, 25 May 2024 21:37:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5116713#M8365</guid>
      <dc:creator>ARB65</dc:creator>
      <dc:date>2024-05-25T21:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: Retrospective Detections for DevHome files</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5116758#M8366</link>
      <description>&lt;P&gt;I’m seeing them too. Assumed false positive but the ThreatGrid Indicators aren’t ones we can ignore until Cisco confirms or not. Hoping to receive another routine “Known False Positive” email from them soon.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 May 2024 02:25:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5116758#M8366</guid>
      <dc:creator>EricHatt</dc:creator>
      <dc:date>2024-05-26T02:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: Retrospective Detections for DevHome files</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5116876#M8367</link>
      <description>&lt;P&gt;I am seeing CSE retrospectively quarantining these files from MS DevHome app:&lt;/P&gt;&lt;P&gt;DevHome.EnvironmentVariables.exe -&amp;nbsp;c22d299aadceb1c008c1feeb2a94ec9d7c9af537f21506fbc6dde91107a2ae20&lt;BR /&gt;DevHome.HostsFileEditor.exe - 7628f84be0ca01762351718d01af3a9c5e7b44ea40508173c53cb178be8d2ee9&lt;BR /&gt;DevHome.RegistryPreview.exe - 47f2ecbbc1f812b63042c8b0a1132956e8fd3ebad3296b8fd4e65f89d5b1cdd5&lt;/P&gt;&lt;P&gt;VT check says that there are only 2 detections for these files (Google, ClamAV)&lt;BR /&gt;These are parts of new 0.14 version which included those files from PowerToy:&lt;BR /&gt;"Utilities are now in Dev Home, including Hosts File Editor, Registry Preview, and Environment Variables editor from PowerToys. (#2795)"&lt;BR /&gt;&lt;A href="https://github.com/microsoft/devhome/releases/tag/v0.1401.505.0" target="_blank"&gt;https://github.com/microsoft/devhome/releases/tag/v0.1401.505.0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Seems like a False Positive to me.&lt;/P&gt;</description>
      <pubDate>Sun, 26 May 2024 09:32:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5116876#M8367</guid>
      <dc:creator>hanculak</dc:creator>
      <dc:date>2024-05-26T09:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: Retrospective Detections for DevHome files</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5116898#M8368</link>
      <description>&lt;P&gt;100 new detections this morning&lt;/P&gt;</description>
      <pubDate>Sun, 26 May 2024 11:11:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5116898#M8368</guid>
      <dc:creator>MidwestCyber</dc:creator>
      <dc:date>2024-05-26T11:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: Retrospective Detections for DevHome files</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5116939#M8369</link>
      <description>&lt;P&gt;Had the same detection yesterday.&lt;/P&gt;</description>
      <pubDate>Sun, 26 May 2024 13:53:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5116939#M8369</guid>
      <dc:creator>gresco-amp</dc:creator>
      <dc:date>2024-05-26T13:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: Retrospective Detections for DevHome files</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5116947#M8370</link>
      <description>&lt;P&gt;When I spoke to the engineer for my TAC case he said TALOS would not be reviewing these until Monday.&amp;nbsp; When I told him that was unacceptable due to the type of files being detected he submitted them to TALOS as high priority to get them to be reviewed sooner.&amp;nbsp; I would suggest you do the same if you are getting these detections.&lt;/P&gt;</description>
      <pubDate>Sun, 26 May 2024 14:15:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5116947#M8370</guid>
      <dc:creator>ARB65</dc:creator>
      <dc:date>2024-05-26T14:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: Retrospective Detections for DevHome files</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5117795#M8371</link>
      <description>&lt;P&gt;Yes there was incident over the weekend, TALSO already rectified these on Sunday so there shouldn't be more incidents.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;These 6 files were flagged by Secure Malware Analytics.&amp;nbsp; After review, we determined that they are all benign, and was actually flagged piggybacking ClamAV detection.&amp;nbsp; The cloud dispositions have been reverted back to 'unknown.'&amp;nbsp; And we went ahead and removed the ClamAV detection as well.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;c22d299aadceb1c008c1feeb2a94ec9d7c9af537f21506fbc6dde91107a2ae20&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;47f2ecbbc1f812b63042c8b0a1132956e8fd3ebad3296b8fd4e65f89d5b1cdd5&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;7557d33ec129946d026caa456e3480d01d44b637abbbc0a92bbf4d023c214273&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;726d06e31ffadc0ebb5eb196b8337d21e102f298e8f32e42978ccda29e4272da&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;7628f84be0ca01762351718d01af3a9c5e7b44ea40508173c53cb178be8d2ee9&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;b74d7d744e5a91b285e34b4b5359803d2bf46da18dbe3747aaf1dd1e4be34a41&lt;/STRONG&gt; &lt;BR /&gt;&lt;BR /&gt;How ever they might be other. So far I was able to collect this list The last 5 are new that were just submit for review.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;849f5e35c3e4da91815655ee0008f460abfd62ed6ed82f1d86c60ac1030e6fb3 Pas.WebApi.exe&lt;BR /&gt;33f59d71810ca02406d550732b1909cf652a3fd574847829271f2e4339117fbd parallelsclient.exe&lt;BR /&gt;f45504fd5ce917e6c7b18ad1a02dd7161f4acd48083b68f458bc97cd2b1ee6ba Veradigm.PartnerPortal.Api.exe&lt;BR /&gt;672d756a15fb144b8cbbc4a0e64dfaed62f6e00cd32423a39148a584a13b40d4 ConsoleApp2.exe&lt;BR /&gt;e12308ab1846b1ae4403fe62fa803cf7c96b6848b5e64e16468c8591109e248c payload.vsix&lt;BR /&gt;c22d299aadceb1c008c1feeb2a94ec9d7c9af537f21506fbc6dde91107a2ae20 DevHome.EnvironmentVariables.exe&lt;BR /&gt;47f2ecbbc1f812b63042c8b0a1132956e8fd3ebad3296b8fd4e65f89d5b1cdd5 DevHome.RegistryPreview.exe&lt;BR /&gt;7557d33ec129946d026caa456e3480d01d44b637abbbc0a92bbf4d023c214273 dotnet-apphost-pack-6.0.30-win-x64.msi&lt;BR /&gt;726d06e31ffadc0ebb5eb196b8337d21e102f298e8f32e42978ccda29e4272da dotnet-apphost-pack-7.0.19-win-x64.ms&lt;BR /&gt;7628f84be0ca01762351718d01af3a9c5e7b44ea40508173c53cb178be8d2ee9 DevHome.HostsFileEditor.exe&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;NEW reported on&amp;nbsp; 05/27&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;I suspect these other 5 files are generated using dotnet so most likely related to the main event.&lt;BR /&gt;&lt;BR /&gt;849f5e35c3e4da91815655ee0008f460abfd62ed6ed82f1d86c60ac1030e6fb3 Pas.WebApi.exe 33f59d71810ca02406d550732b1909cf652a3fd574847829271f2e4339117fbd parallelsclient.exe f45504fd5ce917e6c7b18ad1a02dd7161f4acd48083b68f458bc97cd2b1ee6ba Veradigm.PartnerPortal.Api.exe 672d756a15fb144b8cbbc4a0e64dfaed62f6e00cd32423a39148a584a13b40d4 ConsoleApp2.exe e12308ab1846b1ae4403fe62fa803cf7c96b6848b5e64e16468c8591109e248c payload.vsix &lt;BR /&gt;&lt;BR /&gt;Hope this help...&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 16:32:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5117795#M8371</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2024-05-27T16:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: Retrospective Detections for DevHome files</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5117809#M8372</link>
      <description>&lt;P&gt;The disposition for the following 5 hashes have already been updated to "Unknown."&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;849f5e35c3e4da91815655ee0008f460abfd62ed6ed82f1d86c60ac1030e6fb3 Pas.WebApi.exe 33f59d71810ca02406d550732b1909cf652a3fd574847829271f2e4339117fbd parallelsclient.exe f45504fd5ce917e6c7b18ad1a02dd7161f4acd48083b68f458bc97cd2b1ee6ba Veradigm.PartnerPortal.Api.exe 672d756a15fb144b8cbbc4a0e64dfaed62f6e00cd32423a39148a584a13b40d4 ConsoleApp2.exe e12308ab1846b1ae4403fe62fa803cf7c96b6848b5e64e16468c8591109e248c payload.vsix&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 17:08:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5117809#M8372</guid>
      <dc:creator>DaphneG</dc:creator>
      <dc:date>2024-05-27T17:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: Retrospective Detections for DevHome files</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5117883#M8373</link>
      <description>&lt;P&gt;Adding 6 more new one identified and already rectified as well.&lt;BR /&gt;&lt;BR /&gt;abd7293f22247cbee87e176e61d366d0aa52e623473e9fd045b1e4a22c24f5a1&lt;BR /&gt;cacc4a48f9ca12940ea7cd6660d548978b5a40656c28321bedcca60d35b03dfe&lt;BR /&gt;b76acc53d2cc28f51291fad5b82a1bcbc519518ba8c5daa6af6bd0ac3a74f6ee&lt;BR /&gt;76a618bf49e8238dad4cd993b0358b76a751e205c44489c015b9853f22f169a0&lt;BR /&gt;fdf33cb9b86d3b50cfb40096738e7d9aef9565a585a3e40d9d6a003b4cb3b58f&lt;BR /&gt;80f9f1f0108bca538aed1dcd0a7aedcbec89b3ff44c50e03ac7b01ea75cf53f8&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 19:20:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrospective-detections-for-devhome-files/m-p/5117883#M8373</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2024-05-27T19:20:56Z</dc:date>
    </item>
  </channel>
</rss>

