<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Correlation rules and BIOCs in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-and-biocs/m-p/543210#M4428</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/271703"&gt;@FabioFerreira&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For BIOC and correlation rules first I would recommend to start looking at threats you've seen in the past that weren't properly blocked or reported according to your organization's SOPs.&amp;nbsp; Once that job has been handled sufficiently and your SOC team has matured I recommend looking outside of your organization and looking and new TTPs and threats that are being seen in the wild and build IOCs and correlations rules to match that activity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I understand this may not be the information you're looking for, but no one outside of your organization is going to be able to tell you exactly what you need to be looking for.&amp;nbsp; Different threats are more prevalent in certain industries/verticals than others.&amp;nbsp; Also, everyone's team is at a different level of maturity.'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this information helps.&lt;/P&gt;</description>
    <pubDate>Wed, 24 May 2023 15:08:10 GMT</pubDate>
    <dc:creator>anlynch</dc:creator>
    <dc:date>2023-05-24T15:08:10Z</dc:date>
    <item>
      <title>Correlation rules and BIOCs</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-and-biocs/m-p/543202#M4423</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What correlation rules and BIOCs created manually do you suggest?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Fábio Ferreira&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 14:43:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-and-biocs/m-p/543202#M4423</guid>
      <dc:creator>FabioFerreira</dc:creator>
      <dc:date>2023-05-24T14:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation rules and BIOCs</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-and-biocs/m-p/543210#M4428</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/271703"&gt;@FabioFerreira&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For BIOC and correlation rules first I would recommend to start looking at threats you've seen in the past that weren't properly blocked or reported according to your organization's SOPs.&amp;nbsp; Once that job has been handled sufficiently and your SOC team has matured I recommend looking outside of your organization and looking and new TTPs and threats that are being seen in the wild and build IOCs and correlations rules to match that activity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I understand this may not be the information you're looking for, but no one outside of your organization is going to be able to tell you exactly what you need to be looking for.&amp;nbsp; Different threats are more prevalent in certain industries/verticals than others.&amp;nbsp; Also, everyone's team is at a different level of maturity.'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this information helps.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 15:08:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-and-biocs/m-p/543210#M4428</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-05-24T15:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation rules and BIOCs</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-and-biocs/m-p/543329#M4437</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/232716"&gt;@anlynch&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your reply.&lt;/P&gt;
&lt;P&gt;Sorry if I was not clear.&lt;/P&gt;
&lt;P&gt;We are already doing that and that information we don't need.&lt;/P&gt;
&lt;P&gt;I totally agree when you say, "&lt;SPAN&gt;no one outside of your organization is going to be able to tell you exactly what you need to be looking for&lt;/SPAN&gt;"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was looking for something more generic.&lt;/P&gt;
&lt;P&gt;Let me know if you or someone could &lt;SPAN&gt;suggest&amp;nbsp;&lt;/SPAN&gt;some generic XQL or BIOC rules that could help us leverage our defenses.&lt;/P&gt;
&lt;P&gt;Sharing that kind of information will for sure help all community, I believe &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Fábio Ferreira&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 12:40:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-and-biocs/m-p/543329#M4437</guid>
      <dc:creator>FabioFerreira</dc:creator>
      <dc:date>2023-05-25T12:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation rules and BIOCs</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-and-biocs/m-p/555505#M5046</link>
      <description>&lt;P&gt;You can look into OSINT data bases like Sigma and analyze if it make sense to your organisation and the telemetry you are collecting and can work from there. Rules may be a bit noisy so obviously need to tune out things based on your org. Hope it helps&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 10:37:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/correlation-rules-and-biocs/m-p/555505#M5046</guid>
      <dc:creator>AshokBabu</dc:creator>
      <dc:date>2023-08-28T10:37:33Z</dc:date>
    </item>
  </channel>
</rss>

