<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking Domain/URL in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-domain-url/m-p/328654#M107</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133144"&gt;@Marsooq-Akkaradathil&lt;/a&gt;&amp;nbsp;-&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The current version of the product can only block an IP Address.&amp;nbsp; You can, create an IOC that will alert on this.&amp;nbsp; If you use XSOAR, you could also action on the IOC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dfalcon_0-1589860006792.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25687iA044F764C646BB44/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="dfalcon_0-1589860006792.png" alt="dfalcon_0-1589860006792.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 May 2020 03:48:02 GMT</pubDate>
    <dc:creator>dfalcon</dc:creator>
    <dc:date>2020-05-19T03:48:02Z</dc:date>
    <item>
      <title>Blocking Domain/URL</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-domain-url/m-p/328138#M104</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know we can block IP addresses with new feature called host firewall,.Since the ip is dynamic , its not a good option for me. Is it possible to block url or domain in cortex xdr?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2020 07:29:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-domain-url/m-p/328138#M104</guid>
      <dc:creator>Marsooq-Akkaradathil</dc:creator>
      <dc:date>2020-05-15T07:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Domain/URL</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-domain-url/m-p/328654#M107</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133144"&gt;@Marsooq-Akkaradathil&lt;/a&gt;&amp;nbsp;-&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The current version of the product can only block an IP Address.&amp;nbsp; You can, create an IOC that will alert on this.&amp;nbsp; If you use XSOAR, you could also action on the IOC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dfalcon_0-1589860006792.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25687iA044F764C646BB44/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="dfalcon_0-1589860006792.png" alt="dfalcon_0-1589860006792.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2020 03:48:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-domain-url/m-p/328654#M107</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-05-19T03:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Domain/URL</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-domain-url/m-p/460532#M1477</link>
      <description>&lt;P&gt;Great thank you! Hope they add the new feature to block also domains if not URL with the host firewall. Till then if the customer also has Palo Alto firewalls maybe this is an option for the Cortex XDR to generate EDL lists that the Palo Alto firewall (Palo Alto Firewall and Cortex XDR integration) can consume:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/response-actions/manage-external-dynamic-lists.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/response-actions/manage-external-dynamic-lists.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also it is good to enable the firewalls access to the Cortex XDR and for the firewall to send its logs to the Cortex Data Lake so the Cortex XDR can see the network taffic:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/get-started-with-cortex-xdr-prevent/set-up-endpoint-protection/enable-access-to-cortex-xdr.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/get-started-with-cortex-xdr-prevent/set-up-endpoint-protection/enable-access-to-cortex-xdr.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/blog/2020/03/cortex-busted-by-cortex-xdr/" target="_blank" rel="noopener"&gt;https://www.paloaltonetworks.com/blog/2020/03/cortex-busted-by-cortex-xdr/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 10:47:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-domain-url/m-p/460532#M1477</guid>
      <dc:creator>NikolayDimitrov</dc:creator>
      <dc:date>2022-01-24T10:47:27Z</dc:date>
    </item>
  </channel>
</rss>

