<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alert USB activity in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-usb-activity/m-p/438490#M1122</link>
    <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I check is there any one create a alert if a user copied more than a certain number of files into a USB drive?&lt;/P&gt;&lt;P&gt;Thank You, Cheers!&lt;/P&gt;</description>
    <pubDate>Mon, 04 Oct 2021 15:47:14 GMT</pubDate>
    <dc:creator>BoonHwee</dc:creator>
    <dc:date>2021-10-04T15:47:14Z</dc:date>
    <item>
      <title>Alert USB activity</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-usb-activity/m-p/438490#M1122</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I check is there any one create a alert if a user copied more than a certain number of files into a USB drive?&lt;/P&gt;&lt;P&gt;Thank You, Cheers!&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 15:47:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-usb-activity/m-p/438490#M1122</guid>
      <dc:creator>BoonHwee</dc:creator>
      <dc:date>2021-10-04T15:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: Alert USB activity</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-usb-activity/m-p/438505#M1124</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179841"&gt;@BoonHwee&lt;/a&gt;&amp;nbsp;Cortex XDR analytics offers the ability to detect and alert anomalies with USB storage activity. The following are just two XDR analytics alert references:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Possible data exfiltration over a USB storage device&lt;/LI&gt;&lt;LI&gt;Possible internal data exfiltration over a USB storage device&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Please note,&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-analytics-alert-reference/cortex-xdr-analytics-alert-reference.html" target="_self"&gt;Cortex XDR analytics&lt;/A&gt; requires an XDR Pro license, and the USB Storage Device alerts have required data sources (Palo Alto Networks Firewall Logs and XDR agent), and a required detection module with the &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/analytics/analytics-concepts.html#:~:text=with%20content%20updates.-,Identity%20Analytics,-To%20help%20you" target="_self"&gt;Identity Analytics&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In terms of XDR Device Control, the feature is designed to block or allow USB-connected removable devices depending on how you have configured your Device Configuration - Extensions profile.&amp;nbsp; If I understand the scope of your question correctly, then the device control configuration option is not available at this time. If you would like to request feature enhancements to device control / alerting, then please coordinate with your XDR SE or Customer Success POCs where applicable.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 16:31:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-usb-activity/m-p/438505#M1124</guid>
      <dc:creator>WSeldenIII</dc:creator>
      <dc:date>2021-10-04T16:31:17Z</dc:date>
    </item>
  </channel>
</rss>

