<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XDR Analytics BIOC Alert exclusion in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-analytics-bioc-alert-exclusion/m-p/514344#M2786</link>
    <description>&lt;P&gt;Hello dear community members!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how would you exclude this? It is only popping up in one of our houses/domains.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe this way?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-analytics-specific-exceptions-and-vendor-exceptions/m-p/512786#M2672" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-analytics-specific-exceptions-and-vendor-exceptions/m-p/512786#M2672&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RFeyertag_0-1662674033598.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43751i2042164BB5066236/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="RFeyertag_0-1662674033598.png" alt="RFeyertag_0-1662674033598.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Sep 2022 21:55:58 GMT</pubDate>
    <dc:creator>RFeyertag</dc:creator>
    <dc:date>2022-09-08T21:55:58Z</dc:date>
    <item>
      <title>XDR Analytics BIOC Alert exclusion</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-analytics-bioc-alert-exclusion/m-p/514344#M2786</link>
      <description>&lt;P&gt;Hello dear community members!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how would you exclude this? It is only popping up in one of our houses/domains.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe this way?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-analytics-specific-exceptions-and-vendor-exceptions/m-p/512786#M2672" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-analytics-specific-exceptions-and-vendor-exceptions/m-p/512786#M2672&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RFeyertag_0-1662674033598.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43751i2042164BB5066236/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="RFeyertag_0-1662674033598.png" alt="RFeyertag_0-1662674033598.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 21:55:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-analytics-bioc-alert-exclusion/m-p/514344#M2786</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-09-08T21:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Analytics BIOC Alert exclusion</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-analytics-bioc-alert-exclusion/m-p/514435#M2801</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;Yes, you could take a similar approach as the link in your post to create an exclusion for these alerts.&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;If you wanted to only exclude these types of alerts for specific processes or domains, you could do the following:&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI class=""&gt;Navigate to Detection Rules&amp;gt;BIOC&amp;gt;Analytics BIOC Rules&lt;/LI&gt;
&lt;LI class=""&gt;Edit your layout so that “Global Rule ID” is one of the columns that is displayed in your view&lt;/LI&gt;
&lt;LI class=""&gt;Copy the Rule ID for the BIOC rule you wish to create an exclusion for, in this case - “Recurring rare domain access from an unsigned process”&lt;/LI&gt;
&lt;LI class=""&gt;Navigate to Incident Response&amp;gt;Incident Configuration&amp;gt;Alert Exclusions and click “Add Alert Exclusions”&lt;/LI&gt;
&lt;LI class=""&gt;In your filter, select the “Rule ID” field, select the “=“ operator, and paste the Rule ID value you copied in step 3 as the value. Click “+AND” to add another expression to your filter and choose either the “Initiated By” field (to exclude by process name) or the “Remote Host” field (to exclude by destination domain), select the “=“ operator, and set the value equal to the name of the process or domain generating the alerts you would like to exclude.&lt;/LI&gt;
&lt;LI class=""&gt;Enter a Policy Name/Comment and click "Create" to finish creating the Alert Exclusion.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;BR /&gt;Regards,&lt;/P&gt;
&lt;P&gt;Tim&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 16:15:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-analytics-bioc-alert-exclusion/m-p/514435#M2801</guid>
      <dc:creator>timurphy</dc:creator>
      <dc:date>2022-09-09T16:15:16Z</dc:date>
    </item>
  </channel>
</rss>

