<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hidden User Created | CtxPkmService in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/hidden-user-created-ctxpkmservice/m-p/5144926#M8431</link>
    <description>&lt;P&gt;Thank you for bringing this False Positive to our attention. We also had a TAC case filed on this and the issue has since been resolved. If you see the issue occur again, please open a TAC case so we can get it addressed quickly.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Matt&lt;/P&gt;</description>
    <pubDate>Mon, 15 Jul 2024 12:20:17 GMT</pubDate>
    <dc:creator>Matthew Franks</dc:creator>
    <dc:date>2024-07-15T12:20:17Z</dc:date>
    <item>
      <title>Hidden User Created | CtxPkmService</title>
      <link>https://community.cisco.com/t5/endpoint-security/hidden-user-created-ctxpkmservice/m-p/5144912#M8429</link>
      <description>&lt;P&gt;Good morning,&lt;/P&gt;&lt;P&gt;Anyone else who uses Citrix and Secure Endpoint seeing alerts for Hidden User Created with the value&amp;nbsp;CtxPkmService&amp;nbsp;being added into&amp;nbsp;\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList ?&lt;/P&gt;&lt;P&gt;This looks a FP to me. Started happening past 24 hours.&lt;BR /&gt;Thank you for your time and help.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 11:48:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/hidden-user-created-ctxpkmservice/m-p/5144912#M8429</guid>
      <dc:creator>ventaran</dc:creator>
      <dc:date>2024-07-15T11:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: Hidden User Created | CtxPkmService</title>
      <link>https://community.cisco.com/t5/endpoint-security/hidden-user-created-ctxpkmservice/m-p/5144918#M8430</link>
      <description>&lt;P&gt;Hi there!&lt;/P&gt;&lt;P&gt;We have had the same Issue last Thursday.&amp;nbsp;It appears that the alert is related to a specific Citrix version update to the Workspace Client. We consider it a false positive, especially since no hidden user has been created permanently.&lt;/P&gt;&lt;P&gt;Regards, Frank&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 12:03:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/hidden-user-created-ctxpkmservice/m-p/5144918#M8430</guid>
      <dc:creator>flindemann</dc:creator>
      <dc:date>2024-07-15T12:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Hidden User Created | CtxPkmService</title>
      <link>https://community.cisco.com/t5/endpoint-security/hidden-user-created-ctxpkmservice/m-p/5144926#M8431</link>
      <description>&lt;P&gt;Thank you for bringing this False Positive to our attention. We also had a TAC case filed on this and the issue has since been resolved. If you see the issue occur again, please open a TAC case so we can get it addressed quickly.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 12:20:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/hidden-user-created-ctxpkmservice/m-p/5144926#M8431</guid>
      <dc:creator>Matthew Franks</dc:creator>
      <dc:date>2024-07-15T12:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: Hidden User Created | CtxPkmService</title>
      <link>https://community.cisco.com/t5/endpoint-security/hidden-user-created-ctxpkmservice/m-p/5144958#M8432</link>
      <description>&lt;P&gt;This is still occurring Matt.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're seeing these 'Hidden User Created' detections for the Citrix 'CtxPkmService' alerts from AMP as recently as 15 minutes ago.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 12:53:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/hidden-user-created-ctxpkmservice/m-p/5144958#M8432</guid>
      <dc:creator>TaylorOfTheCave</dc:creator>
      <dc:date>2024-07-15T12:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: Hidden User Created | CtxPkmService</title>
      <link>https://community.cisco.com/t5/endpoint-security/hidden-user-created-ctxpkmservice/m-p/5144972#M8433</link>
      <description>&lt;P&gt;Interesting. I'll reach out to the developers and see what we can do. Do you have a TAC case open I can reference?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 13:16:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/hidden-user-created-ctxpkmservice/m-p/5144972#M8433</guid>
      <dc:creator>Matthew Franks</dc:creator>
      <dc:date>2024-07-15T13:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: Hidden User Created | CtxPkmService</title>
      <link>https://community.cisco.com/t5/endpoint-security/hidden-user-created-ctxpkmservice/m-p/5144975#M8434</link>
      <description>&lt;P&gt;I'd suggest trying to update your signatures considering that is how it was resolved.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MatthewFranks_0-1721049538842.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/223450i0FE5113C93F6BED3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MatthewFranks_0-1721049538842.png" alt="MatthewFranks_0-1721049538842.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;In case that doesn't work, what connector version are you on?&lt;/P&gt;
&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 13:19:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/hidden-user-created-ctxpkmservice/m-p/5144975#M8434</guid>
      <dc:creator>Matthew Franks</dc:creator>
      <dc:date>2024-07-15T13:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: Hidden User Created | CtxPkmService</title>
      <link>https://community.cisco.com/t5/endpoint-security/hidden-user-created-ctxpkmservice/m-p/5144995#M8435</link>
      <description>&lt;P&gt;I do see all of the clients who reported the FP also did Signature/Policy/Component updates within a few minutes of the detection so my expectation is that these clients had been offline since before the update was pushed via policy and they just did the scan/detection before they did the signature update.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've updated our TAC case to reference that it's likely due to an order-of-operations issue with the definition update and the scan.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 14:04:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/hidden-user-created-ctxpkmservice/m-p/5144995#M8435</guid>
      <dc:creator>TaylorOfTheCave</dc:creator>
      <dc:date>2024-07-15T14:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: Hidden User Created | CtxPkmService</title>
      <link>https://community.cisco.com/t5/endpoint-security/hidden-user-created-ctxpkmservice/m-p/5145039#M8436</link>
      <description>&lt;P&gt;We had a similar issue that started on July 9 and continued to July 12.&amp;nbsp; Was correlated with a Citrix Receiver update.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 15:36:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/hidden-user-created-ctxpkmservice/m-p/5145039#M8436</guid>
      <dc:creator>jplopper</dc:creator>
      <dc:date>2024-07-15T15:36:04Z</dc:date>
    </item>
  </channel>
</rss>

