<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best way to exclude legitimate behaviours in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-exclude-legitimate-behaviours/m-p/470492#M1606</link>
    <description>&lt;P&gt;Hello In the second line above do you mean ' I add it as alert exclusion ' or ' I add it as alert exemption ' ?&lt;/P&gt;</description>
    <pubDate>Fri, 04 Mar 2022 10:55:47 GMT</pubDate>
    <dc:creator>Balaraju</dc:creator>
    <dc:date>2022-03-04T10:55:47Z</dc:date>
    <item>
      <title>Best way to exclude legitimate behaviours</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-exclude-legitimate-behaviours/m-p/352162#M337</link>
      <description>&lt;P&gt;When it comes to excluding legitimate behaviours from BIOC rules, as far as I can see, there are 3 options:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Modify the BIOC rule itself adding "not equal to" logic.&lt;/LI&gt;&lt;LI&gt;Add BIOC rule exclusion at&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/" target="_blank"&gt;https://&amp;lt;organisation&amp;gt;.xdr.eu.paloaltonetworks.com/rules/exceptions&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;Add incident / alert exclusion at&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/" target="_self"&gt;https://&amp;lt;organisation&amp;gt;.xdr.eu.paloaltonetworks.com/exclusion&lt;/A&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;What is the recommended way and differences between these methods?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 15:46:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-exclude-legitimate-behaviours/m-p/352162#M337</guid>
      <dc:creator>BenHooper</dc:creator>
      <dc:date>2020-09-25T15:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: Best way to exclude legitimate behaviours</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-exclude-legitimate-behaviours/m-p/359337#M366</link>
      <description>&lt;P&gt;While I'm awaiting a reply, just so others know, a side effect of modifying an existing BIOC rules is that a significant number of its alerts / incidents get re-created.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 11:35:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-exclude-legitimate-behaviours/m-p/359337#M366</guid>
      <dc:creator>BenHooper</dc:creator>
      <dc:date>2020-10-28T11:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: Best way to exclude legitimate behaviours</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-exclude-legitimate-behaviours/m-p/365196#M391</link>
      <description>&lt;P&gt;BenHooper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not saying this is the "recommended" way for excluding legitimate behaviors,&amp;nbsp; but what I have done so far.&lt;/P&gt;&lt;P&gt;When an alert is created, and verifying that it is legitimate, I add it as an alert exclusion.&lt;/P&gt;&lt;P&gt;The thought being that the alert exclusion would be a smaller print versus excluding the whole BIOC rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;DJohnson84&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 13:05:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-exclude-legitimate-behaviours/m-p/365196#M391</guid>
      <dc:creator>DJohnson84</dc:creator>
      <dc:date>2020-11-24T13:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: Best way to exclude legitimate behaviours</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-exclude-legitimate-behaviours/m-p/470492#M1606</link>
      <description>&lt;P&gt;Hello In the second line above do you mean ' I add it as alert exclusion ' or ' I add it as alert exemption ' ?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 10:55:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-exclude-legitimate-behaviours/m-p/470492#M1606</guid>
      <dc:creator>Balaraju</dc:creator>
      <dc:date>2022-03-04T10:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: Best way to exclude legitimate behaviours</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-exclude-legitimate-behaviours/m-p/470807#M1621</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/210067"&gt;@Balaraju&lt;/a&gt;&amp;nbsp;both rule (alert) exceptions and alert exclusions exist in Cortex XDR.&lt;/P&gt;&lt;P&gt;When you exclude an alert, the alert will still be triggered by the agent and sent to XDR tenant. However, it will not be stitched into an incident. Here the action is performed by the XDR tenant. The alerts will appear in the Alerts table.&lt;/P&gt;&lt;P&gt;On the other hand,&amp;nbsp;an alert exception will cause the alert not to be triggered by the agent. The action is performed by the agent.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 05:47:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-exclude-legitimate-behaviours/m-p/470807#M1621</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-03-07T05:47:17Z</dc:date>
    </item>
  </channel>
</rss>

