<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic May this cmd for password query could find into a content update? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/may-this-cmd-for-password-query-could-find-into-a-content-update/m-p/523216#M3215</link>
    <description>&lt;P&gt;&lt;A href="https://twitter.com/VirtualAllocEx/status/1599048829084794880?s=20&amp;amp;t=V1OyrvuCbhYez-wkSXNk1A" target="_blank"&gt;https://twitter.com/VirtualAllocEx/status/1599048829084794880?s=20&amp;amp;t=V1OyrvuCbhYez-wkSXNk1A&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or ist there a rule ready for this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
    <pubDate>Sat, 03 Dec 2022 22:25:35 GMT</pubDate>
    <dc:creator>RFeyertag</dc:creator>
    <dc:date>2022-12-03T22:25:35Z</dc:date>
    <item>
      <title>May this cmd for password query could find into a content update?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/may-this-cmd-for-password-query-could-find-into-a-content-update/m-p/523216#M3215</link>
      <description>&lt;P&gt;&lt;A href="https://twitter.com/VirtualAllocEx/status/1599048829084794880?s=20&amp;amp;t=V1OyrvuCbhYez-wkSXNk1A" target="_blank"&gt;https://twitter.com/VirtualAllocEx/status/1599048829084794880?s=20&amp;amp;t=V1OyrvuCbhYez-wkSXNk1A&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or ist there a rule ready for this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Sat, 03 Dec 2022 22:25:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/may-this-cmd-for-password-query-could-find-into-a-content-update/m-p/523216#M3215</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-12-03T22:25:35Z</dc:date>
    </item>
    <item>
      <title>Re: May this cmd for password query could find into a content update?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/may-this-cmd-for-password-query-could-find-into-a-content-update/m-p/523222#M3218</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Dear&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Thank you for writing to XDR live community!&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;You can create your own &lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xdr-indicators/working-with-biocs/create-a-bioc-rule" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;custom BIOC rule&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; to detect this attempt to discover unsecured credentials in the registry.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Start by logging in to your XDR tenant and Choose Detection Rules → BIOC&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;In the BIOC rules page choose ‘add BIOC’ at the top right of your screen.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;&amp;nbsp;Next, select to create a Process based BIOC and apply the following filters:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;name = reg.exe&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;cmd =~.*query.*password.*&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Click ‘Save’.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;You will now be prompted to name your new BIOC rule and, choose: type, severity level and associated MITRE techniques and tactics:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Type:‘Credentials Access’.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Technique:T1214 - Credentials in Registry&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Tactic: TA0006 - Credential Access&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Click save.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;Attaching screenshots below for your convenience .&lt;BR /&gt;&lt;SPAN&gt;You should now have a custom BIOC to help you discover potential attempts to unsecure credentials in the registry.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Hope this helps!&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Dec 2022 19:24:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/may-this-cmd-for-password-query-could-find-into-a-content-update/m-p/523222#M3218</guid>
      <dc:creator>mavraham</dc:creator>
      <dc:date>2022-12-04T19:24:57Z</dc:date>
    </item>
  </channel>
</rss>

