<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic BIOC - Powershell Script Based Alert Detection in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-powershell-script-based-alert-detection/m-p/481787#M1902</link>
    <description>&lt;P&gt;We know that Cortex has the ability to use AMSI but is any one able to achieve a BIOC rule which can trigger an alert for the content inside the script.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lets say if a Powershell script which is being run has certain parameters in the body such as "replace","Download","Invoke-WebRequest" etc...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to create a BIOC rule for the content inside in the script?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in Advance.&lt;/P&gt;</description>
    <pubDate>Thu, 21 Apr 2022 23:13:55 GMT</pubDate>
    <dc:creator>KanwarSingh01</dc:creator>
    <dc:date>2022-04-21T23:13:55Z</dc:date>
    <item>
      <title>BIOC - Powershell Script Based Alert Detection</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-powershell-script-based-alert-detection/m-p/481787#M1902</link>
      <description>&lt;P&gt;We know that Cortex has the ability to use AMSI but is any one able to achieve a BIOC rule which can trigger an alert for the content inside the script.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lets say if a Powershell script which is being run has certain parameters in the body such as "replace","Download","Invoke-WebRequest" etc...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to create a BIOC rule for the content inside in the script?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in Advance.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 23:13:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-powershell-script-based-alert-detection/m-p/481787#M1902</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2022-04-21T23:13:55Z</dc:date>
    </item>
    <item>
      <title>Re: BIOC - Powershell Script Based Alert Detection</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-powershell-script-based-alert-detection/m-p/502857#M2179</link>
      <description>&lt;P&gt;Hi&amp;nbsp;KanwarSingh01,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The Cortex XDR Agent features Behavioral Threat Protection modules leveraging the Anti-Malware Scan Interface (AMSI) to block PowerShell scripts.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To create a BIOC rule, please check out Live Community How-to video&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/script-block-query-and-bioc/ta-p/347277" target="_blank"&gt;Script Block Query and BIOC | Palo Alto Networks&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 21:01:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-powershell-script-based-alert-detection/m-p/502857#M2179</guid>
      <dc:creator>jtalton</dc:creator>
      <dc:date>2022-06-10T21:01:47Z</dc:date>
    </item>
  </channel>
</rss>

