<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: A question from the Alert Tuning Operations Webinar: PA Repository in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-alert-tuning-operations-webinar-pa/m-p/505698#M2264</link>
    <description>&lt;P&gt;To add more context XDR directly integrates with Autofocus, VIrustotal (requires API key from the customer) and Wildfire in order to provide TI information about indicators. More information &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/get-started-with[…]gure-xdr/integrate-external-threat-intelligence-services" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jun 2022 07:50:39 GMT</pubDate>
    <dc:creator>SilviuMihailDascalu</dc:creator>
    <dc:date>2022-06-23T07:50:39Z</dc:date>
    <item>
      <title>A question from the Alert Tuning Operations Webinar: PA Repository</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-alert-tuning-operations-webinar-pa/m-p/505507#M2251</link>
      <description>&lt;P&gt;1. Does PA have a repository of IOC to import to XDR?&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp;&lt;SPAN&gt;2. Does PA have a repository of Alert Exclusions to import to XDR? For example well known windows process and BIOC.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;*Note: This question was submitted during our customer success webinar: Alert Tuning Operation in Cortex XDR&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 21:04:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-alert-tuning-operations-webinar-pa/m-p/505507#M2251</guid>
      <dc:creator>rtsedaka</dc:creator>
      <dc:date>2022-06-22T21:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: A question from the Alert Tuning Operations Webinar: PA Repository</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-alert-tuning-operations-webinar-pa/m-p/505551#M2256</link>
      <description>&lt;P&gt;1) This is a feature of Threat Intelligence Management from Cortex XSOAR, you can ingest lists from Palo Alto Networks and other 3rd party sources and pass them in to Cortex XDR.&amp;nbsp; You can reach out to your account/sales team for details&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Cortex XDR BIOCs as well as Analytics BIOCs are already tested against well known, safe, activity to reduce false positives, there is no action required for most out of the box Windows systems.&amp;nbsp; If you are encountering false positives related to known trusted Windows processes, you can utilize the concepts discussed in the alert tuning webinar to implement appropriate exceptions/exclusions&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 21:53:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-alert-tuning-operations-webinar-pa/m-p/505551#M2256</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2022-06-22T21:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: A question from the Alert Tuning Operations Webinar: PA Repository</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-alert-tuning-operations-webinar-pa/m-p/505698#M2264</link>
      <description>&lt;P&gt;To add more context XDR directly integrates with Autofocus, VIrustotal (requires API key from the customer) and Wildfire in order to provide TI information about indicators. More information &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/get-started-with[…]gure-xdr/integrate-external-threat-intelligence-services" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 07:50:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/a-question-from-the-alert-tuning-operations-webinar-pa/m-p/505698#M2264</guid>
      <dc:creator>SilviuMihailDascalu</dc:creator>
      <dc:date>2022-06-23T07:50:39Z</dc:date>
    </item>
  </channel>
</rss>

