<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Limitations Cortex XDR Pro with Threat Intelligence Feeds in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/limitations-cortex-xdr-pro-with-threat-intelligence-feeds/m-p/531366#M3646</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1 Yes, with the API below, You can upload indicators by CSV or Json format.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-API-Reference/Insert-Simple-Indicators-CSV" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-API-Reference/Insert-Simple-Indicators-CSV&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2 There is no known size limitation but ofcourse file format should be correct.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3 With current API endpoints, You can write your code (parsing data, uploading via api). If you are asking, will TI Management be part of the XDR ? Currently Yes, XSIAM already has capability to manage TI.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;4 If this is for any type of data, You cannot. You need to have XDR Pro per TB license. If you have, There multiple ways like using BrokerVM, XDR Collectors etc.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;5 This is not possible with XDR Pro. You can upload IOC data with XDR Pro license But IOC uploading is not uploading data into specific dataset if you would like to keep your indicators in specific dataset, XDR Pro per TB requires.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Feb 2023 08:44:51 GMT</pubDate>
    <dc:creator>etugriceri</dc:creator>
    <dc:date>2023-02-16T08:44:51Z</dc:date>
    <item>
      <title>Limitations Cortex XDR Pro with Threat Intelligence Feeds</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/limitations-cortex-xdr-pro-with-threat-intelligence-feeds/m-p/531304#M3642</link>
      <description>&lt;P&gt;Hello dear community,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd like to know more about how you fill your IOCs in Cortex XDR Pro.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are so many TI Feeds outside:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.comparitech.com/net-admin/best-threat-intelligence-feeds/" target="_blank"&gt;https://www.comparitech.com/net-admin/best-threat-intelligence-feeds/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd would prefer the low cost variant (XDR Pro is not the cheapest one). Here are my questions:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Does Cortex XDR Pro offer a API for uploading IOCs?&lt;/P&gt;
&lt;P&gt;2. When uploading it manually, what are the limitations and requiements?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. Will there be a better service in future for TI enrichment without to spend 100k (like for XSOAR + TI Feeds)&lt;/P&gt;
&lt;P&gt;4. How do you get the data to Cortex XDR Pro ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;5. What are the limitations for uploading feed data through a new lookup in a dataset into Cortex XDR Pro?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 21:12:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/limitations-cortex-xdr-pro-with-threat-intelligence-feeds/m-p/531304#M3642</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-02-15T21:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: Limitations Cortex XDR Pro with Threat Intelligence Feeds</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/limitations-cortex-xdr-pro-with-threat-intelligence-feeds/m-p/531366#M3646</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1 Yes, with the API below, You can upload indicators by CSV or Json format.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-API-Reference/Insert-Simple-Indicators-CSV" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-API-Reference/Insert-Simple-Indicators-CSV&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2 There is no known size limitation but ofcourse file format should be correct.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3 With current API endpoints, You can write your code (parsing data, uploading via api). If you are asking, will TI Management be part of the XDR ? Currently Yes, XSIAM already has capability to manage TI.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;4 If this is for any type of data, You cannot. You need to have XDR Pro per TB license. If you have, There multiple ways like using BrokerVM, XDR Collectors etc.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;5 This is not possible with XDR Pro. You can upload IOC data with XDR Pro license But IOC uploading is not uploading data into specific dataset if you would like to keep your indicators in specific dataset, XDR Pro per TB requires.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 08:44:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/limitations-cortex-xdr-pro-with-threat-intelligence-feeds/m-p/531366#M3646</guid>
      <dc:creator>etugriceri</dc:creator>
      <dc:date>2023-02-16T08:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: Limitations Cortex XDR Pro with Threat Intelligence Feeds</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/limitations-cortex-xdr-pro-with-threat-intelligence-feeds/m-p/531664#M3660</link>
      <description>&lt;DIV id="bodyDisplay_0" class=""&gt;
&lt;DIV class=""&gt;
&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;!&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1 Yes, with the API below, You can upload indicators by CSV or Json format.&lt;BR /&gt;&lt;SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-API-Reference/Insert-Simple-Indicators-CSV" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-API-Reference/Insert-Simple-Indicat...&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. Thank you, I will have look. Why are there different informations about the scanning IOCs? Or is it not the same which is written here?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Working-with-IOCs" target="_blank" rel="noopener"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Working-with-IOCs&amp;nbsp;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-API-Reference/Start-an-XQL-Query" target="_blank" rel="noopener"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-API-Reference/Start-an-XQL-Query&amp;nbsp;&lt;SPAN&gt;2 There is no known size limitation but ofcourse file format should be correct.&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. Isn't a 4 Million IOC Storage a limitation?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3 With current API endpoints, You can write your code (parsing data, uploading via api). If you are asking, will TI Management be part of the XDR ? Currently Yes, XSIAM already has capability to manage TI.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3. I am not amused about this product marketing, there could be one product with all the add-ons, but the core should get more and better features like in XSIAM.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4 If this is for any type of data, You cannot. You need to have XDR Pro per TB license. If you have, There multiple ways like using BrokerVM, XDR Collectors etc.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4. Thank you!&amp;nbsp;&lt;BR /&gt;5 This is not possible with XDR Pro. You can upload IOC data with XDR Pro license But IOC uploading is not uploading data into specific dataset if you would like to keep your indicators in specific dataset, XDR Pro per TB requires.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;5. Thank you!&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;BR&lt;BR /&gt;&lt;BR /&gt;Rob&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-API-Reference/Start-an-XQL-Query" target="_blank" rel="noopener"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RFeyertag_1-1676843330132.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48078iDB05470A6EBA8168/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="RFeyertag_1-1676843330132.png" alt="RFeyertag_1-1676843330132.png" /&gt;&lt;/span&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Working-with-IOCs" target="_blank" rel="noopener"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RFeyertag_0-1676843224906.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48077i7D1358C10F2DCF74/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="RFeyertag_0-1676843224906.png" alt="RFeyertag_0-1676843224906.png" /&gt;&lt;/span&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179256"&gt;@etugriceri&lt;/a&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Sun, 19 Feb 2023 21:58:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/limitations-cortex-xdr-pro-with-threat-intelligence-feeds/m-p/531664#M3660</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-02-19T21:58:21Z</dc:date>
    </item>
  </channel>
</rss>

