<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic BIOC Analytics Specific Exceptions and Vendor Exceptions in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-analytics-specific-exceptions-and-vendor-exceptions/m-p/512786#M2672</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;I have encountered multiple occurrences in which a specific process raise many of the same BIOC Analytics Alert. I understand that engine is based on server side and as a customer we are not privy to see what calculations are done on our behalf. In regards to Exclusion, exclusion can only be carried out for the entire alert.&lt;/P&gt;
&lt;P&gt;1) Is there a way to individually exclude certain processes that are causing many of the same BIOC Analytics alerts ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) Is it possible to define on the XDR Tenant that you use an additional security product by a different vendor and that no alerts should be raised by their behaviour including BIOC Analytics?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my experience the BIOC Analytics Mechanism is very powerful yet lacks this fundamental flexibility.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Aug 2022 06:41:46 GMT</pubDate>
    <dc:creator>michaelsysec242</dc:creator>
    <dc:date>2022-08-24T06:41:46Z</dc:date>
    <item>
      <title>BIOC Analytics Specific Exceptions and Vendor Exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-analytics-specific-exceptions-and-vendor-exceptions/m-p/512786#M2672</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;I have encountered multiple occurrences in which a specific process raise many of the same BIOC Analytics Alert. I understand that engine is based on server side and as a customer we are not privy to see what calculations are done on our behalf. In regards to Exclusion, exclusion can only be carried out for the entire alert.&lt;/P&gt;
&lt;P&gt;1) Is there a way to individually exclude certain processes that are causing many of the same BIOC Analytics alerts ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) Is it possible to define on the XDR Tenant that you use an additional security product by a different vendor and that no alerts should be raised by their behaviour including BIOC Analytics?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my experience the BIOC Analytics Mechanism is very powerful yet lacks this fundamental flexibility.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2022 06:41:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-analytics-specific-exceptions-and-vendor-exceptions/m-p/512786#M2672</guid>
      <dc:creator>michaelsysec242</dc:creator>
      <dc:date>2022-08-24T06:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: BIOC Analytics Specific Exceptions and Vendor Exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-analytics-specific-exceptions-and-vendor-exceptions/m-p/512854#M2688</link>
      <description>&lt;P&gt;Hi Michaelsysec242,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. If you are wanting to exclude Analytic BIOC alerts based on process, you can do this through an Exclusion Policy. Navigate to Incident Response &amp;gt; Incident Configuration &amp;gt; Alert Exclusions &amp;gt; +Add Alert Exclusions. Here you can define a policy to exclude alerts based on any combination of criteria using the table filters. For example I could filter on &lt;EM&gt;Alert Source = XDR Analytics BIOC and Initiated By = someGoodProcess.exe&lt;/EM&gt;. This would Exclude any Analytic BIOC alert that is initiated by the defined process. Keep in mind, Exclusion policies do not change XDR behavior, they only exclude these alerts from being viewable or generating Incidents, So if you create Exclusion policies for alerts generated from the XDR agent, there is the risk of excluding traffic that could still be blocked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. There is no capability to universally allow specific software in the platform. For any agent side detections such as the Malware and Exploit protection modules, you would need to ensure each module is set to allow the specific processes, then for all other alert types such as Analytics, BIOC, IOC etc. you can create Exclusion policies as mentioned above.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Ben&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2022 14:50:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-analytics-specific-exceptions-and-vendor-exceptions/m-p/512854#M2688</guid>
      <dc:creator>bbucao</dc:creator>
      <dc:date>2022-08-24T14:50:05Z</dc:date>
    </item>
  </channel>
</rss>

