<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IOC Upload automation in Cortex XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ioc-upload-automation-in-cortex-xdr/m-p/536389#M3936</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi ,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It looks like you're wanting to upload a list&lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Create-an-IOC-Rule" target="_blank"&gt; &lt;SPAN&gt;IOCs&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; to Cortex XDR.&amp;nbsp; Please see the sceenshot below for a look at the steps to Upload a File for IOC Rules.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anlynch_0-1679688850528.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49014iD39980221B053521/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anlynch_0-1679688850528.png" alt="anlynch_0-1679688850528.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I downloaded the example file to get an idea of what it should look like.&amp;nbsp; You can see the sample file below.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anlynch_1-1679688850323.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49012iDE0B60324C0AE678/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anlynch_1-1679688850323.png" alt="anlynch_1-1679688850323.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;IOCs come in the form of Full Path, File Name, Domain, Destination IP, and MD5 or SHA256 Hash.&amp;nbsp; In your text (.txt) file you should place each IOC on it's own line.&amp;nbsp; Cortex XDR has the ability to parse these IOCs and add them appropriately without any additional steps on your end.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When uploading your IOC file you'll be given to the option of what type of IOCs you've entered.&amp;nbsp; You can do a 'Mixed' list as Cortex XDR has the ability to parse these IOCs and add them appropriately without any additional steps on your end.&amp;nbsp; Or a upload a list that only contains 1 type of IOC i.e. File Name.&amp;nbsp; Cortex XDR has the ability to parse these IOCs and add them appropriately without any additional steps on your end.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anlynch_2-1679688850387.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49013i7CB2FFAE7535DBF2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anlynch_2-1679688850387.png" alt="anlynch_2-1679688850387.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Uploading an IOC list also has one additional required selection which is severity.&amp;nbsp; From there you can choose any of the options below depending on your individual needs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anlynch_3-1679688850338.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49015iB0F7DC54159B999C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anlynch_3-1679688850338.png" alt="anlynch_3-1679688850338.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Above I described the manual way to add IOCs to Cortex XDR by uploading a file.&amp;nbsp; If you’re looking to do this process programmatically it would require use of the &lt;/SPAN&gt;&lt;A href="https://cortex-panw.stoplight.io/docs/cortex-xdr/axpm6b98x4p18-cortex-xdr-api-overview" target="_blank"&gt;&lt;SPAN&gt;Cortex XDR API&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If the route you want to go is using the API I’m going to leave some resources down below.&amp;nbsp; There are several ways you can interact with the API including writing your own script in Python, Powershell, cURL, or Postman.&amp;nbsp; It really comes down to what you’re comfortable with.&amp;nbsp; Take a look at these resources and if you have any more questions please let me know.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-articles/cortex-xdr-postman-api-collection/ta-p/443667" target="_blank"&gt;&lt;SPAN&gt;Cortex XDR Postman API Collection&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://cortex-panw.stoplight.io/docs/cortex-xdr/9c8d6942105e6-insert-simple-indicators-csv" target="_blank"&gt;&lt;SPAN&gt;Insert Simple Indicators, CSV&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;I hope you find this information helpful.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 24 Mar 2023 20:14:22 GMT</pubDate>
    <dc:creator>anlynch</dc:creator>
    <dc:date>2023-03-24T20:14:22Z</dc:date>
    <item>
      <title>IOC Upload automation in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ioc-upload-automation-in-cortex-xdr/m-p/536338#M3929</link>
      <description>&lt;P&gt;Hello dear community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone of you a ready to upload script for IOCs to cortex XDR (directly) from a file? Could you share it?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How and where do you handle the doublettes?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 14:52:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ioc-upload-automation-in-cortex-xdr/m-p/536338#M3929</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2023-03-24T14:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: IOC Upload automation in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ioc-upload-automation-in-cortex-xdr/m-p/536389#M3936</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi ,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It looks like you're wanting to upload a list&lt;/SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Create-an-IOC-Rule" target="_blank"&gt; &lt;SPAN&gt;IOCs&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; to Cortex XDR.&amp;nbsp; Please see the sceenshot below for a look at the steps to Upload a File for IOC Rules.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anlynch_0-1679688850528.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49014iD39980221B053521/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anlynch_0-1679688850528.png" alt="anlynch_0-1679688850528.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I downloaded the example file to get an idea of what it should look like.&amp;nbsp; You can see the sample file below.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anlynch_1-1679688850323.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49012iDE0B60324C0AE678/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anlynch_1-1679688850323.png" alt="anlynch_1-1679688850323.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;IOCs come in the form of Full Path, File Name, Domain, Destination IP, and MD5 or SHA256 Hash.&amp;nbsp; In your text (.txt) file you should place each IOC on it's own line.&amp;nbsp; Cortex XDR has the ability to parse these IOCs and add them appropriately without any additional steps on your end.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When uploading your IOC file you'll be given to the option of what type of IOCs you've entered.&amp;nbsp; You can do a 'Mixed' list as Cortex XDR has the ability to parse these IOCs and add them appropriately without any additional steps on your end.&amp;nbsp; Or a upload a list that only contains 1 type of IOC i.e. File Name.&amp;nbsp; Cortex XDR has the ability to parse these IOCs and add them appropriately without any additional steps on your end.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anlynch_2-1679688850387.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49013i7CB2FFAE7535DBF2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anlynch_2-1679688850387.png" alt="anlynch_2-1679688850387.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Uploading an IOC list also has one additional required selection which is severity.&amp;nbsp; From there you can choose any of the options below depending on your individual needs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anlynch_3-1679688850338.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49015iB0F7DC54159B999C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anlynch_3-1679688850338.png" alt="anlynch_3-1679688850338.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Above I described the manual way to add IOCs to Cortex XDR by uploading a file.&amp;nbsp; If you’re looking to do this process programmatically it would require use of the &lt;/SPAN&gt;&lt;A href="https://cortex-panw.stoplight.io/docs/cortex-xdr/axpm6b98x4p18-cortex-xdr-api-overview" target="_blank"&gt;&lt;SPAN&gt;Cortex XDR API&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If the route you want to go is using the API I’m going to leave some resources down below.&amp;nbsp; There are several ways you can interact with the API including writing your own script in Python, Powershell, cURL, or Postman.&amp;nbsp; It really comes down to what you’re comfortable with.&amp;nbsp; Take a look at these resources and if you have any more questions please let me know.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-articles/cortex-xdr-postman-api-collection/ta-p/443667" target="_blank"&gt;&lt;SPAN&gt;Cortex XDR Postman API Collection&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://cortex-panw.stoplight.io/docs/cortex-xdr/9c8d6942105e6-insert-simple-indicators-csv" target="_blank"&gt;&lt;SPAN&gt;Insert Simple Indicators, CSV&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;I hope you find this information helpful.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 20:14:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ioc-upload-automation-in-cortex-xdr/m-p/536389#M3936</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-03-24T20:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: IOC Upload automation in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ioc-upload-automation-in-cortex-xdr/m-p/538025#M4064</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/232716"&gt;@anlynch&lt;/a&gt;!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you so much! This is a good summary.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I need to know what is best practise for doubled entries (you get CSV from TI in full) and you upload all IOCs. Does the API mechanism say, hey there is a doublette, I do not import it. Does it halt or does it go on uploading IOCs through API?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 23:18:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ioc-upload-automation-in-cortex-xdr/m-p/538025#M4064</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-04-07T23:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: IOC Upload automation in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ioc-upload-automation-in-cortex-xdr/m-p/538172#M4071</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for clarifying.&amp;nbsp; I'm going to do some research and get back to you as soon as I can.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a great day!&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2023 21:19:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ioc-upload-automation-in-cortex-xdr/m-p/538172#M4071</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-04-10T21:19:23Z</dc:date>
    </item>
    <item>
      <title>Re: IOC Upload automation in Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ioc-upload-automation-in-cortex-xdr/m-p/538721#M4124</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/232716"&gt;@anlynch&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've tested it, it will be overwritten.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;The next question is, why the cleaning mechanism is not working, when we define 15 Minutes from now to the future?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I allready uploaded some IOCs and this is my last question, which needs to be clarified to get this running.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 06:51:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ioc-upload-automation-in-cortex-xdr/m-p/538721#M4124</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2023-04-14T06:51:10Z</dc:date>
    </item>
  </channel>
</rss>

