<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Palo  Alto BIOC rule content error [specific rule] in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/palo-alto-bioc-rule-content-error-specific-rule/m-p/532171#M3700</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;There is an issue with one of the BIOC rules provided by Palo Alto. Specifically in the rule with Global ID "94fed992-c1da-4b69-9caa-292221b8c070".&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;The wildcards for the command line arguments that this rule intents to detect, are off. To be precise all leading wildcards in this detection have a space afterwards, thus rendering the rule unable to detect the actual activity taking place.&lt;BR /&gt;E.g. (not real argument): * test*, while the correct would be *test*.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I have tested this and indeed it does not work as intended right now.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Could you please review it from your side and make the necessary changes or guide me in order to open a ticket/email elsewhere if needed ? But from what I understand, this is not a tenant specific issue, so I thought opening a thread here was more appropriate.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance,&lt;BR /&gt;Ilias&lt;/P&gt;</description>
    <pubDate>Fri, 24 Feb 2023 11:02:30 GMT</pubDate>
    <dc:creator>ithermos</dc:creator>
    <dc:date>2023-02-24T11:02:30Z</dc:date>
    <item>
      <title>Palo  Alto BIOC rule content error [specific rule]</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/palo-alto-bioc-rule-content-error-specific-rule/m-p/532171#M3700</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;There is an issue with one of the BIOC rules provided by Palo Alto. Specifically in the rule with Global ID "94fed992-c1da-4b69-9caa-292221b8c070".&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;The wildcards for the command line arguments that this rule intents to detect, are off. To be precise all leading wildcards in this detection have a space afterwards, thus rendering the rule unable to detect the actual activity taking place.&lt;BR /&gt;E.g. (not real argument): * test*, while the correct would be *test*.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I have tested this and indeed it does not work as intended right now.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Could you please review it from your side and make the necessary changes or guide me in order to open a ticket/email elsewhere if needed ? But from what I understand, this is not a tenant specific issue, so I thought opening a thread here was more appropriate.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance,&lt;BR /&gt;Ilias&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 11:02:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/palo-alto-bioc-rule-content-error-specific-rule/m-p/532171#M3700</guid>
      <dc:creator>ithermos</dc:creator>
      <dc:date>2023-02-24T11:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: Palo  Alto BIOC rule content error [specific rule]</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/palo-alto-bioc-rule-content-error-specific-rule/m-p/532211#M3705</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/269744"&gt;@ithermos&lt;/a&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would recommend opening a TAC case with these findings so that it is properly documented and can be investigated internally by Palo Alto teams.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 18:08:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/palo-alto-bioc-rule-content-error-specific-rule/m-p/532211#M3705</guid>
      <dc:creator>timurphy</dc:creator>
      <dc:date>2023-02-24T18:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: Palo  Alto BIOC rule content error [specific rule]</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/palo-alto-bioc-rule-content-error-specific-rule/m-p/534428#M3835</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;Just a heads up, via TAC case indeed, the resolution is on the way. IMO though, there should be another path for these kinds of issues (rule/content based, global etc).&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Ilias&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 08:22:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/palo-alto-bioc-rule-content-error-specific-rule/m-p/534428#M3835</guid>
      <dc:creator>ithermos</dc:creator>
      <dc:date>2023-03-15T08:22:23Z</dc:date>
    </item>
  </channel>
</rss>

