Bypass Record
Disable or Modify Tools × Palo Alto Networks Cortex XDR Agent
A publicly-reported instance of Disable or Modify Tools bypassing Palo Alto Networks Cortex XDR Agent, recorded with its original source. Factual record; no assessment of any specific deployment.
Mechanism
CVE-2024-5907: The Cortex XDR agent's support file generation creates a predictable temporary folder in C:\Windows\Temp with weak ACLs. By placing a junction (NTFS soft link) in that folder pointing to a target directory, an attacker can force the SYSTEM-level cyserver.exe process to delete arbitrary files/folders during cleanup. Combined with a Windows Installer race condition, this can lead to privilege escalation. CVE-2024-9469: The agent's Adaptive Policy module monitors CPU usage to auto-disable protection under high load. A low-privileged user can artificially inflate CPU usage of the agent's processes, triggering the auto-disable mechanism and turning off all protections.
Detection & mitigation
Monitor for unexpected termination or suspension of Cortex XDR agent processes (e.g., cyserver.exe) and changes to agent configuration or protection status via Windows Event Logs (Security/System) and EDR telemetry. Mitigate by applying vendor patches, restricting local administrative privileges, and hardening file system permissions on temporary folders used by the agent.
This is a record of a publicly-reported event, not an assessment of any specific organization's deployment. Detection and mitigation notes are drawn from the cited source. Where the source is silent, fields are omitted.