<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What the different of alert sources and definition of its. in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-the-different-of-alert-sources-and-definition-of-its/m-p/536713#M3961</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203353"&gt;@JamesWiggins&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LIVEcommunity!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The alert you're mentioning is a known false positive.&amp;nbsp; A bad BIOC rule went out with a Content Update and it is currently being investigated.&amp;nbsp; There will more than likely be updates to the situation on &lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/multiple-events-quot-a-successful-login-from-tor-quot/td-p/536683" target="_self"&gt;this thread&lt;/A&gt; if you'd like to follow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 27 Mar 2023 21:54:28 GMT</pubDate>
    <dc:creator>anlynch</dc:creator>
    <dc:date>2023-03-27T21:54:28Z</dc:date>
    <item>
      <title>What the different of alert sources and definition of its.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-the-different-of-alert-sources-and-definition-of-its/m-p/350908#M327</link>
      <description>&lt;P&gt;XDR Analytics BIOC&lt;BR /&gt;XDR BIOC&lt;BR /&gt;PAN NGFW&lt;BR /&gt;XDR IOC&lt;BR /&gt;XDR Analytics&lt;BR /&gt;XDR Managed Threat Hunting&lt;BR /&gt;XDR Agent&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 18:50:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-the-different-of-alert-sources-and-definition-of-its/m-p/350908#M327</guid>
      <dc:creator>Komdet</dc:creator>
      <dc:date>2020-09-21T18:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: What the different of alert sources and definition of its.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-the-different-of-alert-sources-and-definition-of-its/m-p/357954#M363</link>
      <description>&lt;P&gt;Would also love to hear or see more about this question.&lt;/P&gt;&lt;P&gt;Responding to it in hopes it will pop on the top of the queue for more folks to see and perhaps share info or resources&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 20:38:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-the-different-of-alert-sources-and-definition-of-its/m-p/357954#M363</guid>
      <dc:creator>KRisselada</dc:creator>
      <dc:date>2020-10-21T20:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: What the different of alert sources and definition of its.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-the-different-of-alert-sources-and-definition-of-its/m-p/364488#M383</link>
      <description>&lt;P&gt;&lt;STRONG&gt;XDR Analytics BIOC&lt;/STRONG&gt; - These are analytics alerts based (mainly) on single events. They are similar to BIOCs, except they also account for a&amp;nbsp; profile of how common or rare something is. Examples are "Uncommon local scheduled task creation via schtasks.exe",&amp;nbsp; "Microsoft Office Process Spawning a Suspicious One-Liner" and "Uncommon user management via net.exe". They are single event (execution of something) that is rarely seen in the environment.&lt;BR /&gt;&lt;STRONG&gt;XDR BIOC&lt;/STRONG&gt; - These are behavioral IOCs, looking for abnormal&amp;nbsp;behavior but not with specific hashes, IPs or domains. An example is&amp;nbsp;&lt;BR /&gt;"&lt;SPAN&gt;Binary file being created to disk with a double extension" - this rule is not looking at who created the file or what the file is, it's looking for the fact that a file was created with this attribute. Another example is "PowerShell runs base64-encoded commands", "Windows certificate management tool makes a network connection" and "Script file added to startup-related Registry keys".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NGFW&lt;/STRONG&gt; - These are alerts generated by Palo Alto Network Next Gen Firewall as traffic is going through it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;XDR IOC&lt;/STRONG&gt; - These are simple IOC matches, including hashes, IPs, domains, files, etc.&lt;BR /&gt;&lt;STRONG&gt;XDR Analytics&lt;/STRONG&gt; - There alerts are similar to Analytics BIOCs, however they are multi-event. An example can be "Random-Looking Domain Names" - this alert groups multiple DNS queries that seem random and alerts when it sees several of them. Additional examples are&amp;nbsp;"Recurring Rare Domain Access", "Failed Connections" and "DNS Tunneling".&lt;BR /&gt;&lt;STRONG&gt;XDR Managed Threat Hunting&lt;/STRONG&gt; - These are alert generated by our Managed Service.&lt;BR /&gt;&lt;STRONG&gt;XDR Agent&lt;/STRONG&gt; - These are alerts generated by the agent itself on the machines. All other alert type above (expect the FW) are generated using the telemetry XDR collects in the cloud, but this one is done by the agent locally when it sees suspicious behavior in real time. Alerts can be malware related, restrictions, exploits and more.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 09:29:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-the-different-of-alert-sources-and-definition-of-its/m-p/364488#M383</guid>
      <dc:creator>ocohen</dc:creator>
      <dc:date>2020-11-20T09:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: What the different of alert sources and definition of its.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-the-different-of-alert-sources-and-definition-of-its/m-p/536679#M3950</link>
      <description>&lt;P&gt;Where can I go to see the exact definition of the alerts? Specifically trying to see the definition of XDR's Analytics BIOC "A Successful login from TOR"&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 21:14:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-the-different-of-alert-sources-and-definition-of-its/m-p/536679#M3950</guid>
      <dc:creator>JamesWiggins</dc:creator>
      <dc:date>2023-03-27T21:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: What the different of alert sources and definition of its.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-the-different-of-alert-sources-and-definition-of-its/m-p/536713#M3961</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203353"&gt;@JamesWiggins&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LIVEcommunity!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The alert you're mentioning is a known false positive.&amp;nbsp; A bad BIOC rule went out with a Content Update and it is currently being investigated.&amp;nbsp; There will more than likely be updates to the situation on &lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/multiple-events-quot-a-successful-login-from-tor-quot/td-p/536683" target="_self"&gt;this thread&lt;/A&gt; if you'd like to follow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 21:54:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-the-different-of-alert-sources-and-definition-of-its/m-p/536713#M3961</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-03-27T21:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: What the different of alert sources and definition of its.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-the-different-of-alert-sources-and-definition-of-its/m-p/536787#M3975</link>
      <description>&lt;P&gt;Perfect, thank you! Is the exact definition of that alert not listed anywhere?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 12:58:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/what-the-different-of-alert-sources-and-definition-of-its/m-p/536787#M3975</guid>
      <dc:creator>JamesWiggins</dc:creator>
      <dc:date>2023-03-28T12:58:16Z</dc:date>
    </item>
  </channel>
</rss>

