<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Learning Behaviour of Cortex XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/learning-behaviour-of-cortex-xdr/m-p/530805#M3611</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/224150"&gt;@Aiman_Fathima&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank you for reaching out to Live Community. I will try to address your questions:&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Cortex XDR utilizes a wide variety of tools when analyzing user behavior, not just host or initiator processes. &lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;I’ll provide a few examples and concepts you need familiarize yourself with to better understand, I also highlighted the parts I think will be relevant to your question.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;1. &lt;/SPAN&gt;&lt;STRONG&gt;Analytics Engine&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The Cortex XDR app uses its Analytics Engine to examine logs and data retrieved from your sensors on the Cortex XDR tenants &lt;/SPAN&gt;&lt;STRONG&gt;to build an activity baseline, and recognize abnormal activity when it occurs&lt;/STRONG&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The Analytics Engine also creates and maintains the &lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;profiles&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;STRONG&gt;view the activity of the endpoint or user in context by comparing it to similar endpoints or users&lt;/STRONG&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Example:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;A statistical analysis of an entity or an entity relation that compares the same entity to itself over time. For example, a host can have a Profile depending on the number of ports it accessed in the past.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;&lt;STRONG&gt;Analytics Sensors&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;Cortex XDR analyzes logs and data from external and internal sensors such as: firewall traffic logs, &lt;/SPAN&gt;&lt;SPAN&gt;enhanced application logs, Windows events collector logs and others.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;&lt;STRONG&gt;MITRE Attack Tactics&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;The Analytics Engine can raise an alert for a wide variety of MITRE attack tactics, based on the &lt;/SPAN&gt;&lt;A href="https://attack.mitre.org/" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;&amp;nbsp;MITRE ATT&amp;amp;CK™ knowledge base&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;OL start="4"&gt;
&lt;LI&gt;&lt;STRONG&gt;Analytics Detection Time Intervals&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;This part covers how long it takes Cortex XDR to establish a baseline for analytics. Please note The actual amount of logging data (measured in time) required to raise any given Cortex XDR Analytics alert is identified in the Cortex XDR &lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Analytics-Alert-Reference/Cortex-XDR-Analytics-Alert-Reference" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Analytics Alert Reference Guide&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The Cortex XDR Analytics Engine retrieves logs from the Cortex XDR tenant &lt;/SPAN&gt;&lt;STRONG&gt;to create a baseline so that it can raise alerts when abnormal activity occurs&lt;/STRONG&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;To raise alerts, each detector compares the recent past behavior to the expected baseline by examining the data found in your logs&lt;/STRONG&gt;&lt;SPAN&gt;. A certain amount of log file time is required to establish a baseline and then a certain amount of recent log file time is required to identify what is currently happening in your environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="5"&gt;
&lt;LI&gt;&lt;STRONG&gt;Analytics BIOCs&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;In contrast to standard Analytics alerts, Analytics BIOCs (&lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;ABIOCs&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt;)—indicate a single event of suspicious behavior with an identified chain of causality. To identify the context and chain of causality, &lt;/SPAN&gt;&lt;STRONG&gt;ABIOCs leverage user, endpoint, and network profiles&lt;/STRONG&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;STRONG&gt;The profile is generated by the Analytics Engine and can be based on a simple statistical profile or a more complex machine-learning profile&lt;/STRONG&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;STRONG&gt;Cortex XDR tailors each ABIOC to your specific environment after analyzing your logs and data sources&lt;/STRONG&gt;&lt;SPAN&gt; and continually tunes and delivers new ABIOCs with content updates.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As you can see, Cortex XDR uses many different analytics mechanisms and sources to establish baselines for user behavior.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;You can find more documentation about Cortex XDR Analytics &lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;here&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If this helps, please click ‘Accept as Solution’!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 12 Feb 2023 13:48:07 GMT</pubDate>
    <dc:creator>mavraham</dc:creator>
    <dc:date>2023-02-12T13:48:07Z</dc:date>
    <item>
      <title>Learning Behaviour of Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/learning-behaviour-of-cortex-xdr/m-p/530532#M3597</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We know that cortex XDR takes atleast one month to learn behaviour and then not throw similar alerts.&lt;/P&gt;
&lt;P&gt;1. On what basis is this behaviour learning happening upon?&lt;/P&gt;
&lt;P&gt;2. Is it based on just the Host or initiator processes that are taking place?&lt;/P&gt;
&lt;P&gt;3. If possible, could you please provide some reference documentation on how cortex learning mechanism works.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 18:41:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/learning-behaviour-of-cortex-xdr/m-p/530532#M3597</guid>
      <dc:creator>Aiman_Fathima</dc:creator>
      <dc:date>2023-02-09T18:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: Learning Behaviour of Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/learning-behaviour-of-cortex-xdr/m-p/530805#M3611</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/224150"&gt;@Aiman_Fathima&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank you for reaching out to Live Community. I will try to address your questions:&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Cortex XDR utilizes a wide variety of tools when analyzing user behavior, not just host or initiator processes. &lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;I’ll provide a few examples and concepts you need familiarize yourself with to better understand, I also highlighted the parts I think will be relevant to your question.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;1. &lt;/SPAN&gt;&lt;STRONG&gt;Analytics Engine&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The Cortex XDR app uses its Analytics Engine to examine logs and data retrieved from your sensors on the Cortex XDR tenants &lt;/SPAN&gt;&lt;STRONG&gt;to build an activity baseline, and recognize abnormal activity when it occurs&lt;/STRONG&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The Analytics Engine also creates and maintains the &lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;profiles&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;STRONG&gt;view the activity of the endpoint or user in context by comparing it to similar endpoints or users&lt;/STRONG&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Example:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;A statistical analysis of an entity or an entity relation that compares the same entity to itself over time. For example, a host can have a Profile depending on the number of ports it accessed in the past.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;&lt;STRONG&gt;Analytics Sensors&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;Cortex XDR analyzes logs and data from external and internal sensors such as: firewall traffic logs, &lt;/SPAN&gt;&lt;SPAN&gt;enhanced application logs, Windows events collector logs and others.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;&lt;STRONG&gt;MITRE Attack Tactics&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;The Analytics Engine can raise an alert for a wide variety of MITRE attack tactics, based on the &lt;/SPAN&gt;&lt;A href="https://attack.mitre.org/" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;&amp;nbsp;MITRE ATT&amp;amp;CK™ knowledge base&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;OL start="4"&gt;
&lt;LI&gt;&lt;STRONG&gt;Analytics Detection Time Intervals&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;This part covers how long it takes Cortex XDR to establish a baseline for analytics. Please note The actual amount of logging data (measured in time) required to raise any given Cortex XDR Analytics alert is identified in the Cortex XDR &lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Analytics-Alert-Reference/Cortex-XDR-Analytics-Alert-Reference" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Analytics Alert Reference Guide&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The Cortex XDR Analytics Engine retrieves logs from the Cortex XDR tenant &lt;/SPAN&gt;&lt;STRONG&gt;to create a baseline so that it can raise alerts when abnormal activity occurs&lt;/STRONG&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;To raise alerts, each detector compares the recent past behavior to the expected baseline by examining the data found in your logs&lt;/STRONG&gt;&lt;SPAN&gt;. A certain amount of log file time is required to establish a baseline and then a certain amount of recent log file time is required to identify what is currently happening in your environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="5"&gt;
&lt;LI&gt;&lt;STRONG&gt;Analytics BIOCs&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;In contrast to standard Analytics alerts, Analytics BIOCs (&lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;ABIOCs&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt;)—indicate a single event of suspicious behavior with an identified chain of causality. To identify the context and chain of causality, &lt;/SPAN&gt;&lt;STRONG&gt;ABIOCs leverage user, endpoint, and network profiles&lt;/STRONG&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;STRONG&gt;The profile is generated by the Analytics Engine and can be based on a simple statistical profile or a more complex machine-learning profile&lt;/STRONG&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;STRONG&gt;Cortex XDR tailors each ABIOC to your specific environment after analyzing your logs and data sources&lt;/STRONG&gt;&lt;SPAN&gt; and continually tunes and delivers new ABIOCs with content updates.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As you can see, Cortex XDR uses many different analytics mechanisms and sources to establish baselines for user behavior.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;You can find more documentation about Cortex XDR Analytics &lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;here&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If this helps, please click ‘Accept as Solution’!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Feb 2023 13:48:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/learning-behaviour-of-cortex-xdr/m-p/530805#M3611</guid>
      <dc:creator>mavraham</dc:creator>
      <dc:date>2023-02-12T13:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: Learning Behaviour of Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/learning-behaviour-of-cortex-xdr/m-p/530812#M3614</link>
      <description>&lt;P&gt;Also&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/224150"&gt;@Aiman_Fathima&lt;/a&gt;&amp;nbsp;, Just to add to&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167148"&gt;@mavraham&lt;/a&gt;&amp;nbsp;, post, the learning period of activity is a continuous process and the 1 month you are mentioning is for the initial capability to digest and profile initial baseline. Besides this, analytics engine is a kind of an n-dimensional engine which works on following set of profiles:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Current behaviour&lt;/LI&gt;
&lt;LI&gt;Time Profile&lt;/LI&gt;
&lt;LI&gt;Peer Profile&lt;/LI&gt;
&lt;LI&gt;Entity Profile&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;All of the behaviours have different profiling mechanism and so does their test, train and deduplication(when you say "stop throwing similar alerts") periods.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example, port scan alerts may have test and dedupliaction period of 1 hour and 12 hours respectively, while Large upload may have the same for 1 day for both test train and deduplicate period.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please follow &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR-Analytics-Alert-Reference/Required-Data-Sources" target="_blank" rel="noopener"&gt;Analytics Alerts Reference&lt;/A&gt; page in the Adminitrator Guide for detailed info&lt;/P&gt;</description>
      <pubDate>Sun, 12 Feb 2023 23:16:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/learning-behaviour-of-cortex-xdr/m-p/530812#M3614</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-02-12T23:16:41Z</dc:date>
    </item>
  </channel>
</rss>

