<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Analytic BIOC Rules, right click open in query builder, informational severity not available in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/analytic-bioc-rules-right-click-open-in-query-builder/m-p/486111#M1953</link>
    <description>&lt;P&gt;We have a support ticket open for "informational" analytic BIOC rules that are not alerting.&lt;/P&gt;&lt;P&gt;These do not show up in the incidents or alert table, but the number of alerts in that column has more than 0&lt;/P&gt;&lt;P&gt;Support has indicated there is not a way to view the hits of the rule&lt;/P&gt;&lt;P&gt;Does anyone know a way to view these analytic bioc rule alerts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When viewing normal bioc rules, you can right click and open in query builder.&lt;/P&gt;&lt;P&gt;This option isn't available when looking at analytic bioc rules.&lt;/P&gt;&lt;P&gt;Is there a place or way to view how the rule is structured...what the xql query is?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 May 2022 14:04:57 GMT</pubDate>
    <dc:creator>NathanBradley</dc:creator>
    <dc:date>2022-05-10T14:04:57Z</dc:date>
    <item>
      <title>Analytic BIOC Rules, right click open in query builder, informational severity not available</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/analytic-bioc-rules-right-click-open-in-query-builder/m-p/486111#M1953</link>
      <description>&lt;P&gt;We have a support ticket open for "informational" analytic BIOC rules that are not alerting.&lt;/P&gt;&lt;P&gt;These do not show up in the incidents or alert table, but the number of alerts in that column has more than 0&lt;/P&gt;&lt;P&gt;Support has indicated there is not a way to view the hits of the rule&lt;/P&gt;&lt;P&gt;Does anyone know a way to view these analytic bioc rule alerts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When viewing normal bioc rules, you can right click and open in query builder.&lt;/P&gt;&lt;P&gt;This option isn't available when looking at analytic bioc rules.&lt;/P&gt;&lt;P&gt;Is there a place or way to view how the rule is structured...what the xql query is?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 14:04:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/analytic-bioc-rules-right-click-open-in-query-builder/m-p/486111#M1953</guid>
      <dc:creator>NathanBradley</dc:creator>
      <dc:date>2022-05-10T14:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: Analytic BIOC Rules, right click open in query builder, informational severity not available</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/analytic-bioc-rules-right-click-open-in-query-builder/m-p/486602#M1974</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24508"&gt;@NathanBradley&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The below article can best explain you the logic behind all the ABIOC rules setup in Cortex.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-analytics-alert-reference/cortex-xdr-analytics-alert-reference" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-analytics-alert-reference/cortex-xdr-analytics-alert-reference&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In general, informational alerts will only show up when an incident is triggered and get stitched with other alerts as part of insights in an incident to help better understand the incident.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Speaking for myself, if we start investigating into informational alerts then we will end up chasing false positives but there might be cases where your investigation might lead to a possible suspicious activity.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In order to find the suspicious activity you will first need to know some start point. For example:&lt;/P&gt;&lt;P&gt;In this cases we are looking for a command called "net user" (we created a BIOC rule to detect this command as informational). So lets say the query returned a result from there on we dig into the causality chain and then click on the process itself and then see the activity for alert as informational. (Not the best way to look for informational alert but does the trick.) You can use a similar logic to find ABIOC informational alerts.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KanwarSingh01_1-1652330651374.png" style="width: 789px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40961i6E5EBCD90BBCFC97/image-dimensions/789x500/is-moderation-mode/true?v=v2" width="789" height="500" role="button" title="KanwarSingh01_1-1652330651374.png" alt="KanwarSingh01_1-1652330651374.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You.&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 04:46:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/analytic-bioc-rules-right-click-open-in-query-builder/m-p/486602#M1974</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2022-05-12T04:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: Analytic BIOC Rules, right click open in query builder, informational severity not available</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/analytic-bioc-rules-right-click-open-in-query-builder/m-p/486795#M1981</link>
      <description>&lt;P&gt;Im looking for a way to either see the events that caused the analytic bioc to fire&lt;/P&gt;&lt;P&gt;or a way to view the query behind the rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example the rule below has 7 alerts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NathanBradley_0-1652364269918.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40977i1C2E4A7336791B5D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="NathanBradley_0-1652364269918.png" alt="NathanBradley_0-1652364269918.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 14:05:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/analytic-bioc-rules-right-click-open-in-query-builder/m-p/486795#M1981</guid>
      <dc:creator>NathanBradley</dc:creator>
      <dc:date>2022-05-12T14:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: Analytic BIOC Rules, right click open in query builder, informational severity not available</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/analytic-bioc-rules-right-click-open-in-query-builder/m-p/527282#M3400</link>
      <description>&lt;P&gt;Wondering how I can hunt for BIOC "elevation of privilege" events, for example pertinent to "&lt;SPAN&gt;CVE-2023-21674&amp;nbsp;&lt;/SPAN&gt;"&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 22:05:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/analytic-bioc-rules-right-click-open-in-query-builder/m-p/527282#M3400</guid>
      <dc:creator>SamuelSt</dc:creator>
      <dc:date>2023-01-16T22:05:26Z</dc:date>
    </item>
  </channel>
</rss>

