<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block List not working in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-list-not-working/m-p/512780#M2670</link>
    <description>&lt;P&gt;Hi, and thanks Ben.&lt;/P&gt;
&lt;P&gt;there is way to block IOCs?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;bc alert doesn't help me, in case of attack I don't need to know about it, I need to block it.&lt;/P&gt;</description>
    <pubDate>Wed, 24 Aug 2022 05:59:01 GMT</pubDate>
    <dc:creator>Oriavs</dc:creator>
    <dc:date>2022-08-24T05:59:01Z</dc:date>
    <item>
      <title>Block List not working</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-list-not-working/m-p/512675#M2663</link>
      <description>&lt;P&gt;hey,&lt;/P&gt;
&lt;P&gt;just for testing I created python file and extract the hash. after that added the hash to the "Block List".&lt;/P&gt;
&lt;P&gt;click on "check-it now", run the python file and nothing happened!.&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;someone know what could be the problem?&lt;/P&gt;
&lt;P&gt;thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First pic - the rule.&lt;/P&gt;
&lt;P&gt;Sec pic- the hash&lt;/P&gt;
&lt;P&gt;Third pic - the prove about non block file. (the python script himself)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43315iD7A0D0561E602128/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 13:58:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-list-not-working/m-p/512675#M2663</guid>
      <dc:creator>Oriavs</dc:creator>
      <dc:date>2022-08-23T13:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: Block List not working</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-list-not-working/m-p/512677#M2664</link>
      <description>&lt;P&gt;Hi Oriavs,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The reason this is not working is .py files are not supported for the hash block/allow lists. See the documentation &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-files/manage-file-execution" target="_self"&gt;here&lt;/A&gt; for supported file types by operating system for this functionality.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Ben&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 14:15:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-list-not-working/m-p/512677#M2664</guid>
      <dc:creator>bbucao</dc:creator>
      <dc:date>2022-08-23T14:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: Block List not working</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-list-not-working/m-p/512681#M2667</link>
      <description>&lt;P&gt;Bbucao is correct, what is executing is not the .py file, but the python interpreter, so you can't blacklist a python script directly.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 14:34:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-list-not-working/m-p/512681#M2667</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2022-08-23T14:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Block List not working</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-list-not-working/m-p/512707#M2668</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/219403"&gt;@afurze&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/205598"&gt;@bbucao&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;thanks for answer.&lt;/P&gt;
&lt;P&gt;so, how can I&amp;nbsp;&lt;FONT face="inherit"&gt;block python (or other file type that is not PE) file? or even remove him with cortex?&lt;/FONT&gt;&lt;BR /&gt;I'm&lt;FONT face="inherit"&gt;&amp;nbsp;ask bc I have list of hundreds hashes, and I don't know the type of them.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="inherit"&gt;thanks again!&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 16:44:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-list-not-working/m-p/512707#M2668</guid>
      <dc:creator>Oriavs</dc:creator>
      <dc:date>2022-08-23T16:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: Block List not working</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-list-not-working/m-p/512708#M2669</link>
      <description>&lt;P&gt;Hi Oriavs,&lt;/P&gt;
&lt;P&gt;I imagine these hashes came from some type of threat intel feed? If that is the case and you want to leverage them in Cortex XDR I recommend creating &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xdr-indicators/working-with-iocs/create-an-ioc-rule" target="_self"&gt;IOC rules&lt;/A&gt; by navigating to Detection Rules &amp;gt; IOC &amp;gt; + Add IOC, then you can select to create these rules individually for each hash, or upload via a file. When these rules are created, Cortex XDR will alert anytime these hashes are seen in your logs. Now to be clear, this will not block anything, but will alert you if one of these hashes is seen so you can investigate the traffic. If you are just wanting to search for and remove files based on hash, you can use the File Search and Destroy feature if you have the "Host Insights" add-on license.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 17:03:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-list-not-working/m-p/512708#M2669</guid>
      <dc:creator>bbucao</dc:creator>
      <dc:date>2022-08-23T17:03:15Z</dc:date>
    </item>
    <item>
      <title>Re: Block List not working</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-list-not-working/m-p/512780#M2670</link>
      <description>&lt;P&gt;Hi, and thanks Ben.&lt;/P&gt;
&lt;P&gt;there is way to block IOCs?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;bc alert doesn't help me, in case of attack I don't need to know about it, I need to block it.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2022 05:59:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-list-not-working/m-p/512780#M2670</guid>
      <dc:creator>Oriavs</dc:creator>
      <dc:date>2022-08-24T05:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: Block List not working</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-list-not-working/m-p/512837#M2681</link>
      <description>&lt;P&gt;Hi Oriavs,&lt;BR /&gt;&lt;BR /&gt;As data is streamed into the XDR cloud tenant from your XDR agents or other sources, the IOC rules are applied against that data to identify any matches. Since this is happening in the cloud versus at the agent there is no ability to perform blocking actions on IOC rules.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Cortex XDR uses a multi-method approach to stop both known and unknown threats including behavioral prevention and malware sandboxing which look at the actual behavior a file creates on a system. This is inherently more reliable then tracking static IOC's because one of the easiest things a threat actor can do is change a file hash which makes that IOC useless. It is much harder for the threat actor to change the overall behavior of their malware, or their Tactics Techniques and Procedures. Because of how easy it is to change a files hash, or file name, or change an IP address, static IOC's are known to have a very short shelf life before they become irrelevant compared to more modern and advanced detection methods.&amp;nbsp; I find IOC's are most beneficial in a real-time use-case, where I am responding to an active threat and am pulling these IOC's from the identified malicious traffic in my network, then adding them as rules into Cortex XDR to help identify the scope of the Incident. You can view a list of the endpoint protection modules Cortex XDR leverages &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-concepts/endpoint-protection-modules" target="_self"&gt;here.&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2022 13:22:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-list-not-working/m-p/512837#M2681</guid>
      <dc:creator>bbucao</dc:creator>
      <dc:date>2022-08-24T13:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: Block List not working</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-list-not-working/m-p/512839#M2683</link>
      <description>&lt;P&gt;Thanks about the answer.&lt;/P&gt;
&lt;P&gt;I know &lt;SPAN&gt;behavior&amp;nbsp;is much better then&amp;nbsp;&lt;/SPAN&gt;hashes.&lt;/P&gt;
&lt;P&gt;But still, why I should care about who many hashes in the block list?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have very good sources to receive hashes when attacker release payload to the big world, so why not?&lt;/P&gt;
&lt;P&gt;why Palo Alto don't give me the option to block any type of file?&lt;/P&gt;
&lt;P&gt;thanks again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2022 13:43:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-list-not-working/m-p/512839#M2683</guid>
      <dc:creator>Oriavs</dc:creator>
      <dc:date>2022-08-24T13:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: Block List not working</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-list-not-working/m-p/512896#M2689</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231903"&gt;@Oriavs&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I am following this threat correctly, then you are looking for a way to block file exception based on file hash. You can add sha-256 hashes to the block list within the action center. This workflow is documented in the &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/investigate-files/manage-file-execution" target="_self"&gt;Manage File Execution&lt;/A&gt; tech. doc.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2022 19:48:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-list-not-working/m-p/512896#M2689</guid>
      <dc:creator>WSeldenIII</dc:creator>
      <dc:date>2022-08-24T19:48:46Z</dc:date>
    </item>
  </channel>
</rss>

