<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic BIOC Question in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-question/m-p/536751#M3968</link>
    <description>&lt;P&gt;Hello, Everyone!&lt;/P&gt;
&lt;P&gt;I would like to know how this can be implemented - I want to block suspicious remote control applications (BIOC) Cortex XDR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I want a reply from the Palo Alto official. Thanks.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Mar 2023 04:56:59 GMT</pubDate>
    <dc:creator>Jerome_Detona</dc:creator>
    <dc:date>2023-03-28T04:56:59Z</dc:date>
    <item>
      <title>BIOC Question</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-question/m-p/536751#M3968</link>
      <description>&lt;P&gt;Hello, Everyone!&lt;/P&gt;
&lt;P&gt;I would like to know how this can be implemented - I want to block suspicious remote control applications (BIOC) Cortex XDR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I want a reply from the Palo Alto official. Thanks.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 04:56:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-question/m-p/536751#M3968</guid>
      <dc:creator>Jerome_Detona</dc:creator>
      <dc:date>2023-03-28T04:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: BIOC Question</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-question/m-p/536766#M3972</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/254598"&gt;@Jerome_Detona&lt;/a&gt;&amp;nbsp;I recommend you to go through &lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-file-execution-based-on-nameand-or-bioc-ioc/td-p/441563" target="_blank"&gt;this thread&lt;/A&gt; which describes in detail on how to block hashes without or without BIOC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The question lies in how you go about determining what is "suspicious". Once you have the hash, you can add it to Global Block lists, or via Restriction Profiles for selected endpoints.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 08:07:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-question/m-p/536766#M3972</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2023-03-28T08:07:28Z</dc:date>
    </item>
  </channel>
</rss>

