<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking EFSRPC in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-efsrpc/m-p/550119#M4803</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/130057"&gt;@Kyle_Begle&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Just to add while looking into the activity that caused the alert you can "Debug alert" to see the interesting fields which can be used for creating BIOC and then you &lt;SPAN&gt;can configure BIOC rules as&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="proto-highlight"&gt;custom&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="proto-highlight"&gt;prevention&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;rules and incorporate them with your Restrictions profiles as shared above by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/232716"&gt;@anlynch&lt;/a&gt;&amp;nbsp;.&lt;BR /&gt;Screenshot for reference:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PiyushKohli_0-1689822671748.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/51811iA4EA38D813344BDC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PiyushKohli_0-1689822671748.png" alt="PiyushKohli_0-1689822671748.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Ref:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Working-with-BIOCs" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Working-with-BIOCs&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jul 2023 03:12:11 GMT</pubDate>
    <dc:creator>PiyushKohli</dc:creator>
    <dc:date>2023-07-20T03:12:11Z</dc:date>
    <item>
      <title>Blocking EFSRPC</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-efsrpc/m-p/550034#M4794</link>
      <description>&lt;P&gt;In the &lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-articles/content-release-notes/ta-p/257570" target="_blank" rel="noopener"&gt;7/17 content release notes&lt;/A&gt;, improvements have been made to "Suspicious Encrypting File System Remote call (EFSRPC) to domain controller' generated by XDR Analytics BIOC detected on 2 hosts."&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;By default, the action for this is to detect/alert. I would like to change this to block. Does anyone know how to accomplish this? Better yet, what is the best way to determine which cortex settings/policies apply to a specific Incident? Is there some master list of Incident types and respective settings?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I looked through Prevention Profiles and could not find a setting that makes sense for the EFSRPC alert. Thanks in advance for any help you can provide.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 16:01:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-efsrpc/m-p/550034#M4794</guid>
      <dc:creator>Kyle_Begle</dc:creator>
      <dc:date>2023-07-19T16:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking EFSRPC</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-efsrpc/m-p/550061#M4799</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/130057"&gt;@Kyle_Begle&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LIVEcommunity!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In regards to the rule you're mentioning it is an analytics BIOC.&amp;nbsp; This means there is not block functionality associated with it.&amp;nbsp; Analytics BIOCs are not produced in real time and therefore cannot block. Please take a look at the &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics-Concepts" target="_self"&gt;Analytics Concepts.&lt;/A&gt;&amp;nbsp;for a better understanding of how analytics work.&amp;nbsp; Essentially it's looking at a lot of different factors after the event to determine the larger picture.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By looking into the activity that caused the alert you may be able to find similarities you can use to create a high fidelity BIOC which can be used to block unwanted activity in your environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope you find this information helpful.&amp;nbsp; Have a great day!&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 20:17:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-efsrpc/m-p/550061#M4799</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-07-19T20:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking EFSRPC</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-efsrpc/m-p/550119#M4803</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/130057"&gt;@Kyle_Begle&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Just to add while looking into the activity that caused the alert you can "Debug alert" to see the interesting fields which can be used for creating BIOC and then you &lt;SPAN&gt;can configure BIOC rules as&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="proto-highlight"&gt;custom&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="proto-highlight"&gt;prevention&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;rules and incorporate them with your Restrictions profiles as shared above by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/232716"&gt;@anlynch&lt;/a&gt;&amp;nbsp;.&lt;BR /&gt;Screenshot for reference:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PiyushKohli_0-1689822671748.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/51811iA4EA38D813344BDC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PiyushKohli_0-1689822671748.png" alt="PiyushKohli_0-1689822671748.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Ref:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Working-with-BIOCs" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Working-with-BIOCs&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 03:12:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/blocking-efsrpc/m-p/550119#M4803</guid>
      <dc:creator>PiyushKohli</dc:creator>
      <dc:date>2023-07-20T03:12:11Z</dc:date>
    </item>
  </channel>
</rss>

