Researchers reported that Palo Alto Networks Cortex XDR behavioral detection rules can be decrypted and analyzed, exposing how the product identifies malicious activity and creating a path for attackers to tune malware and tradecraft to avoid alerts. The reporting describes how BIOC rules, intended to be protected in encrypted form inside the agent, were reverse engineered to reveal internal detection logic, undermining the assumption that the ruleset is opaque to adversaries.
Technical analysis from InfoGuard Labs said the issue affected Cortex XDR Windows agent versions 8.7 and 8.8, where decryption keys could be derived from a hardcoded string and a plaintext Lua configuration file. After translating the proprietary rules into plaintext, researchers identified broad allowlist behavior, including a command-line exception containing \Windows\ccmcache, which reportedly bypassed a large share of behavioral detections and could be abused for stealthy execution and other malicious actions. This is not fluff: it is substantive security research with direct implications for endpoint detection evasion and defensive validation.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
InfoGuard Labs' findings were publicly reported in mid-March 2026, detailing how encrypted BIOC rules could be decrypted and how embedded exceptions could be abused to evade behavioral detections. Coverage noted no cited widespread in-the-wild exploitation but warned that organizations relying on Cortex XDR could face increased evasion risk.
At the end of February 2026, Palo Alto Networks released a fix for the issue in Cortex XDR Agent 9.1 with Content version 2160. The remediation primarily removed the overly permissive global allowlists that enabled the bypass.
InfoGuard Labs reported the Cortex XDR BIOC rule design flaw and evasion technique to Palo Alto Networks. The disclosure occurred in July 2025, starting the vendor remediation process.
While analyzing Palo Alto Networks Cortex XDR Windows agent versions 8.7 and 8.8, InfoGuard Labs reverse-engineered the BIOC rule decryption process, recovered plaintext behavioral rules, and identified a hardcoded global allowlist tied to the command-line string "\Windows\ccmcache". The researchers showed this could be abused to suppress detections, including using ProcDump to dump LSASS memory without alerts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
thecyberexpress.com
Open sourcecybersecuritynews.com
Open sourcelabs.infoguard.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.