<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Correlation rules create incident in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-create-incident/m-p/494008#M2042</link>
    <description>&lt;P&gt;So correlation rules can't trigger a block, am I right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I created a BIOC Rule, here you can see it:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cyber1985_0-1653688620562.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41457i6F04B54FCC677354/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Cyber1985_0-1653688620562.png" alt="Cyber1985_0-1653688620562.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where is the connection missing? I can remember in past I got that connection between BIOC and custom prevention rule which I could find under the restriction profile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But now I can only enable it, but cannot define only my custom once, I don't want cortex to block all BIOCs. How can I deal with that?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cyber1985_1-1653688824752.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41458iE32E7FCBB94B29B9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Cyber1985_1-1653688824752.png" alt="Cyber1985_1-1653688824752.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 27 May 2022 22:02:44 GMT</pubDate>
    <dc:creator>Cyber1985</dc:creator>
    <dc:date>2022-05-27T22:02:44Z</dc:date>
    <item>
      <title>Correlation rules create incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-create-incident/m-p/490147#M2026</link>
      <description>&lt;P&gt;Hey dear sec community!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there a way to setup an correlation rule, which can block and not only detect?&lt;/P&gt;&lt;P&gt;I couldn't find a way. I tried the XQL queries from the libary.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xdr-indicators/working-with-correlation-rules/create-a-correlation-rule" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xdr-indicators/working-with-correlation-rules/create-a-correlation-rule&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 06:09:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-create-incident/m-p/490147#M2026</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-05-24T06:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation rules create incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-create-incident/m-p/490363#M2027</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206384"&gt;@Cyber1985&lt;/a&gt;&amp;nbsp;I believe what you're looking for is &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-profiles/add-restrictions-profile" target="_blank"&gt;Restrictions Profile&lt;/A&gt;. You can create a BIOC and add it to a Restrictions Profile for it to block certain behavior. Please note that this will be a post-execution module.&lt;/P&gt;&lt;P&gt;An example is preventing users from using Google Chrome to visit &lt;A href="https://1.1.1.1" target="_blank"&gt;https://1.1.1.1&lt;/A&gt;. You can write that BIOC and add it a Restrictions Profile, and apply that to an endpoint/set of endpoints via Security policies.&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 09:55:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-create-incident/m-p/490363#M2027</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-05-24T09:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation rules create incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-create-incident/m-p/494008#M2042</link>
      <description>&lt;P&gt;So correlation rules can't trigger a block, am I right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I created a BIOC Rule, here you can see it:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cyber1985_0-1653688620562.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41457i6F04B54FCC677354/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Cyber1985_0-1653688620562.png" alt="Cyber1985_0-1653688620562.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where is the connection missing? I can remember in past I got that connection between BIOC and custom prevention rule which I could find under the restriction profile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But now I can only enable it, but cannot define only my custom once, I don't want cortex to block all BIOCs. How can I deal with that?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cyber1985_1-1653688824752.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41458iE32E7FCBB94B29B9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Cyber1985_1-1653688824752.png" alt="Cyber1985_1-1653688824752.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 22:02:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-create-incident/m-p/494008#M2042</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-05-27T22:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation rules create incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-create-incident/m-p/498912#M2092</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206384"&gt;@Cyber1985&lt;/a&gt;&amp;nbsp;please see the below screenshot where I am able to add it to a Restrictions Profile. I hope this meets your needs.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_0-1654225011171.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41572i45ABDBF7827D93B9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_0-1654225011171.png" alt="bbarmanroy_0-1654225011171.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2022 02:57:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-create-incident/m-p/498912#M2092</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-06-03T02:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation rules create incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-create-incident/m-p/500482#M2115</link>
      <description>&lt;P&gt;Hey! Sure this fits somewhere my needs. But when I create a BIOC Rule out of a XQL, it won't work to put it into a restriction profile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I like XQL and how do I translate it to the "standard input BIOC language"?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2022 17:59:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-create-incident/m-p/500482#M2115</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-06-06T17:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation rules create incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-create-incident/m-p/500502#M2117</link>
      <description>&lt;P&gt;Hi Cyber1985,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are specific restrictions when attempting to use a custom prevention rule through the Restrictions Profile.&amp;nbsp; Link to documentation is here (&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xdr-indicators/working-with-biocs/create-a-bioc-rule" target="_self"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xdr-indicators/working-with-biocs/create-a-bioc-rule&lt;/A&gt;&amp;nbsp;), however, I will summarize below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;To be valid as a BIOC rule, the XQL query must at least filter on event_type&lt;/LI&gt;&lt;LI&gt;To configure a BIOC rule as a prevention rule, the BIOC must not include the following field configurations&lt;UL&gt;&lt;LI&gt;All Eevnts - Host Name&lt;/LI&gt;&lt;LI&gt;File Event - Device Type, Device Serial Number&lt;/LI&gt;&lt;LI&gt;Process Event - Device Type, Device Serial Number&lt;/LI&gt;&lt;LI&gt;Registry Event - Country, Raw Packet&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;If an OS scope is defined, it must match with the Restrictions profile OS type&lt;/LI&gt;&lt;LI&gt;When defining the Process criteria for a user-defined BIOC rule event type, you can select to run only on actor, causality, and OS actor on Windows, and causality and OS actor on Linux and Mac&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Please review your BIOC rule and ensure that it meets these guidelines, if possible, post the BIOC rule here for further troubleshooting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2022 18:29:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-create-incident/m-p/500502#M2117</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2022-06-06T18:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation rules create incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-create-incident/m-p/500609#M2118</link>
      <description>&lt;P&gt;I found out, you should not take the fields and timeframe to your XQL Query, when a BIOC-Rule + Restriction Input should be created out of it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I was able to get my goal &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/219403"&gt;@afurze&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt;&amp;nbsp;!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2022 19:52:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-create-incident/m-p/500609#M2118</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-06-06T19:52:51Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation rules create incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-create-incident/m-p/626572#M7440</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A id="link_12" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206384" target="_self" aria-label="View Profile of Cyber1985"&gt;&lt;SPAN class=""&gt;Cyber1985&lt;/SPAN&gt;&lt;/A&gt;,&lt;/P&gt;
&lt;P&gt;Correlation rules only shows actions as an alert. they do not any capability to block the action&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 10:06:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-create-incident/m-p/626572#M7440</guid>
      <dc:creator>E.Jafarov</dc:creator>
      <dc:date>2024-11-19T10:06:43Z</dc:date>
    </item>
  </channel>
</rss>

