<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to block IOC from Cortex XDR? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511771#M2540</link>
    <description>&lt;P&gt;I think you need to do this from BIOC perspective. Not from the alert/incident perspective.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Aug 2022 19:14:04 GMT</pubDate>
    <dc:creator>RFeyertag</dc:creator>
    <dc:date>2022-08-12T19:14:04Z</dc:date>
    <item>
      <title>Is it possible to block IOC from Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511727#M2529</link>
      <description>&lt;P&gt;I'm trying to block domain across in our environment. I don't want to use url filtering on PA FW, but I want to use XDR IOC to block it. is possible to do it?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 15:50:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511727#M2529</guid>
      <dc:creator>hpatel11</dc:creator>
      <dc:date>2022-08-12T15:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block IOC from Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511728#M2530</link>
      <description>&lt;P&gt;Hi Hpatel11,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately, no, it is not possible to block IOCs with Cortex XDR directly, the IOCs exist only on the XDR server and are not sent to the agents.&amp;nbsp; If you are an XDR Pro per Endpoint or Pro per TB customer, you can set up&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/cortex-xdr-how-to-video-external-dynamic-lists/ta-p/509414" target="_self"&gt;External Dynamic Lists&lt;/A&gt;&amp;nbsp;and have your NGFW subscribe to those lists to automatically update your firewall policy directly from XDR.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 15:40:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511728#M2530</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2022-08-12T15:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block IOC from Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511729#M2531</link>
      <description>&lt;P&gt;I figured. Thanks!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 15:41:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511729#M2531</guid>
      <dc:creator>hpatel11</dc:creator>
      <dc:date>2022-08-12T15:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block IOC from Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511732#M2532</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/172141"&gt;@hpatel11&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if IOCs are hashes you can block them adding them to the block list&lt;/P&gt;
&lt;P&gt;Then as Afurze mentioned you can add other IOCs or internet web-sites to the EDLs so you can block them on your FWs&lt;/P&gt;
&lt;P&gt;Other indicators like malicious email senders can be added (by your own procedures) to email server black lists...&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Think of other tools you might have at your organization in order to appropriately block all kinds of IOCs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps,&amp;nbsp;&lt;BR /&gt;Luis&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 15:48:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511732#M2532</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2022-08-12T15:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block IOC from Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511754#M2533</link>
      <description>&lt;P&gt;I did this in my poc(long time ago), I blocked like &lt;A href="http://www.heise.de" target="_blank"&gt;www.heise.de&lt;/A&gt; through BIOC with restriction rule.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I surfed on this webpage the whole browser got closed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want I can repeat it in my cortex xdr pro per endpoint Environment.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 17:39:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511754#M2533</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-08-12T17:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block IOC from Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511757#M2534</link>
      <description>&lt;P&gt;I checked on BIOC but don't see anything for Domain. I see that we can do by IP.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 17:43:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511757#M2534</guid>
      <dc:creator>hpatel11</dc:creator>
      <dc:date>2022-08-12T17:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block IOC from Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511758#M2535</link>
      <description>&lt;P&gt;Have you tried to take a network query to view which field the domain is called?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 17:52:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511758#M2535</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-08-12T17:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block IOC from Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511761#M2537</link>
      <description>&lt;P&gt;Got it it's called&amp;nbsp;&lt;SPAN&gt;action_external_hostname Let me try to use this.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 18:09:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511761#M2537</guid>
      <dc:creator>hpatel11</dc:creator>
      <dc:date>2022-08-12T18:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block IOC from Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511768#M2538</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hpatel11_0-1660330535523.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43126i8418045C8A417A2B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="hpatel11_0-1660330535523.png" alt="hpatel11_0-1660330535523.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I was able to create BIOC but can't associate BIOC with prevention policy. It's not syntax issue because I was able to trigger alert on it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 18:57:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511768#M2538</guid>
      <dc:creator>hpatel11</dc:creator>
      <dc:date>2022-08-12T18:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block IOC from Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511771#M2540</link>
      <description>&lt;P&gt;I think you need to do this from BIOC perspective. Not from the alert/incident perspective.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 19:14:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511771#M2540</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-08-12T19:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block IOC from Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511775#M2541</link>
      <description>&lt;P&gt;This is only option that we got.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hpatel11_0-1660331748642.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43128i8DBE86E8651695A9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="hpatel11_0-1660331748642.png" alt="hpatel11_0-1660331748642.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hpatel11_1-1660331752536.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43129iAE240F775870F33B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="hpatel11_1-1660331752536.png" alt="hpatel11_1-1660331752536.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 19:16:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511775#M2541</guid>
      <dc:creator>hpatel11</dc:creator>
      <dc:date>2022-08-12T19:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block IOC from Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511781#M2542</link>
      <description>&lt;P&gt;So the guys from PA are right. You can only prevent with BIOC the processes.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At the moment I cannot say why it worked at my POC. I remember, when I opened the page the whole browser went down.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 19:43:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511781#M2542</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-08-12T19:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block IOC from Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511783#M2543</link>
      <description>&lt;P&gt;and by the way, you can add process BIOCs through right clicking and add to restriction profile.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RFeyertag_0-1660333550063.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43131iDC8E8817900708E8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="RFeyertag_0-1660333550063.png" alt="RFeyertag_0-1660333550063.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 19:46:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/511783#M2543</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-08-12T19:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block IOC from Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/512083#M2560</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206384"&gt;@Cyber1985&lt;/a&gt;&amp;nbsp;, please be notified that it is a process activity using network connection to destinations for incoming, outgoing and failed connections only. There is still a possibility for raw packets which is not something can be blocked using Cortex XDR.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additionally, the BIOC rule as resriction actually blocks your browser process action and repetitive actions like these can be risky leading to crashing of the application itself and you might have to reinstall the application again.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 07:41:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/512083#M2560</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2022-08-17T07:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block IOC from Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/512101#M2568</link>
      <description>&lt;P&gt;Thank you very much for this information! I can remember that in my test the complete browser was "closed" automaticly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 12:17:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/512101#M2568</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-08-17T12:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to block IOC from Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/522054#M3175</link>
      <description>&lt;P&gt;I renembered this discussion and in the future if the Palo Alto XDR host firewall can have rules based on DNS FQDN Domains not only IP addresses then this could be possible. Maybe check for Request For enhancment as this could be added as it does not seem so complex but for now as mentioned the option BIOC and to use EDL with your Palo Alto Firewalls or Prisma Access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/hardened-endpoint-security/host-firewall" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/hardened-endpoint-security/host-firewall&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/hardened-endpoint-security/host-firewall/host-firewall-for-windows" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/hardened-endpoint-security/host-firewall/host-firewall-for-windows&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 15:17:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/m-p/522054#M3175</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-11-22T15:17:43Z</dc:date>
    </item>
  </channel>
</rss>

