<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Yara Rules and Cortex XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/yara-rules-and-cortex-xdr/m-p/478171#M1835</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163390"&gt;@KanwarSingh01&lt;/a&gt;&amp;nbsp;Cortex XDR uses several protection modules both on the agent as well as on the tenant-side, including integrations with &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-profiles/add-malware-security-profile/wildfire-analysis-concepts" target="_blank"&gt;Wildfire&lt;/A&gt; as well as other integrations (e.g. VirusTotal) that you may have added to your tenant. They range from behavioral techniques (BTPs/BIOCs), ML models, malware and exploit protection modules, YARA signatures, sandboxes, local analysis etc. These protection modules are both pre-execution and post-execution in nature, as well as both detective/preventative in nature.&lt;BR /&gt;Customers are not able to tune YARA rules in XDR as that is entirely evolving in the backend and is managed by dedicated Threat Hunters, malware researchers and exploit researchers.&amp;nbsp;&lt;BR /&gt;Lastly, your tenant modules are seamlessly upgraded to respond to evolving threats and attacks as observed by the relevant domain experts. On the agent side, please ensure that the CU's are rolled out ASAP while being inline with your organizational security policies. The agents themselves should also be regularly updated to address the vulnerabilities/capability improvements that are packaged with each new minor/maintenance release.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please go through &lt;A href="https://www.paloaltonetworks.com/blog/security-operations/cortex-xdr-protections-against-malware-associated-with-ukraine-and-russia-cyber-activity/" target="_blank"&gt;this article&lt;/A&gt; that talks about XDR's capabilities with recent malware in-the-wild that touches upon the various levels of protection within XDR.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Apr 2022 01:42:26 GMT</pubDate>
    <dc:creator>bbarmanroy</dc:creator>
    <dc:date>2022-04-05T01:42:26Z</dc:date>
    <item>
      <title>Yara Rules and Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/yara-rules-and-cortex-xdr/m-p/477735#M1820</link>
      <description>&lt;P&gt;I have seen alerts screenshot on internet where an alert triggered after matching a Yara rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://attackevals.mitre-engenuity.org/enterprise/participants/paloaltonetworks?adversary=carbanak-fin7&amp;amp;view=results&amp;amp;scenario=1" target="_blank"&gt;https://attackevals.mitre-engenuity.org/enterprise/participants/paloaltonetworks?adversary=carbanak-fin7&amp;amp;view=results&amp;amp;scenario=1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KanwarSingh01_1-1648928772751.png" style="width: 870px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39998i4468255BFFBC365C/image-dimensions/870x50/is-moderation-mode/true?v=v2" width="870" height="50" role="button" title="KanwarSingh01_1-1648928772751.png" alt="KanwarSingh01_1-1648928772751.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;(Fourth Screenshot)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does Cortex XDR uses Yara Rules? I mean the screenshot answers it but how? Do we need to upgrade on a specific version of XDR agent? Can we build our own custom yara rules?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/cortex/cortex-xdr" target="_blank"&gt;https://www.paloaltonetworks.com/cortex/cortex-xdr&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KanwarSingh01_0-1648928403368.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39997iA38F3503CDFDC1CD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="KanwarSingh01_0-1648928403368.png" alt="KanwarSingh01_0-1648928403368.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would love to understand how it works.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Apr 2022 19:49:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/yara-rules-and-cortex-xdr/m-p/477735#M1820</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2022-04-02T19:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: Yara Rules and Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/yara-rules-and-cortex-xdr/m-p/478171#M1835</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163390"&gt;@KanwarSingh01&lt;/a&gt;&amp;nbsp;Cortex XDR uses several protection modules both on the agent as well as on the tenant-side, including integrations with &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-profiles/add-malware-security-profile/wildfire-analysis-concepts" target="_blank"&gt;Wildfire&lt;/A&gt; as well as other integrations (e.g. VirusTotal) that you may have added to your tenant. They range from behavioral techniques (BTPs/BIOCs), ML models, malware and exploit protection modules, YARA signatures, sandboxes, local analysis etc. These protection modules are both pre-execution and post-execution in nature, as well as both detective/preventative in nature.&lt;BR /&gt;Customers are not able to tune YARA rules in XDR as that is entirely evolving in the backend and is managed by dedicated Threat Hunters, malware researchers and exploit researchers.&amp;nbsp;&lt;BR /&gt;Lastly, your tenant modules are seamlessly upgraded to respond to evolving threats and attacks as observed by the relevant domain experts. On the agent side, please ensure that the CU's are rolled out ASAP while being inline with your organizational security policies. The agents themselves should also be regularly updated to address the vulnerabilities/capability improvements that are packaged with each new minor/maintenance release.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please go through &lt;A href="https://www.paloaltonetworks.com/blog/security-operations/cortex-xdr-protections-against-malware-associated-with-ukraine-and-russia-cyber-activity/" target="_blank"&gt;this article&lt;/A&gt; that talks about XDR's capabilities with recent malware in-the-wild that touches upon the various levels of protection within XDR.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 01:42:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/yara-rules-and-cortex-xdr/m-p/478171#M1835</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-04-05T01:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: Yara Rules and Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/yara-rules-and-cortex-xdr/m-p/478483#M1836</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt;&amp;nbsp; are there any plans of integrating Custom Yara Rules in the future?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 20:30:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/yara-rules-and-cortex-xdr/m-p/478483#M1836</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2022-04-05T20:30:58Z</dc:date>
    </item>
    <item>
      <title>Re: Yara Rules and Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/yara-rules-and-cortex-xdr/m-p/478527#M1837</link>
      <description>&lt;P&gt;We are discussing this internally to see what can be done. On a tactical basis, if you're having any issues with any detections, please raise a support ticket.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 02:07:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/yara-rules-and-cortex-xdr/m-p/478527#M1837</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-04-06T02:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: Yara Rules and Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/yara-rules-and-cortex-xdr/m-p/478552#M1839</link>
      <description>&lt;P&gt;Not having issues just questions.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 05:25:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/yara-rules-and-cortex-xdr/m-p/478552#M1839</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2022-04-06T05:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: Yara Rules and Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/yara-rules-and-cortex-xdr/m-p/547318#M4646</link>
      <description>&lt;P&gt;We have a need for custome Yara rules as well.&lt;/P&gt;
&lt;P&gt;Other vendors like Trend Micro do have this already implemented.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any news from internal discussions&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt;?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 17:11:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/yara-rules-and-cortex-xdr/m-p/547318#M4646</guid>
      <dc:creator>MarkusMix</dc:creator>
      <dc:date>2023-06-26T17:11:10Z</dc:date>
    </item>
  </channel>
</rss>

