<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to use BIOC to block specific domains? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-use-bioc-to-block-specific-domains/m-p/551273#M4833</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/251009"&gt;@Chilla&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on your above use case where you want to&amp;nbsp;&lt;SPAN&gt;block specific domains using XDR using BIOC and&amp;nbsp;"&lt;STRONG&gt;Add to restrictions profile&lt;/STRONG&gt;"&amp;nbsp;. Would like to share by using BIOC/BTP this will block/prevent your browser process action as result of which this rule might kill/crash the browser process which could be risky and you might have to reinstall the application again.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In your use case since you want to block specific domains if you are using Palo Alto firewall you may leverage or setup EDL (External Dynamic List) using which you may block the domain and IP.&amp;nbsp;&lt;BR /&gt;Ref: &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-External-Dynamic-Lists" target="_self"&gt;Manage External Dynamic Lists&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/td-p/511727" target="_self"&gt;LC Post&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;However, in case you still want to test using BIOC by adding to restriction&amp;nbsp;profile to block specific domain you may create BIOC like this. Update your domain as required, the one in screenshot is for reference only.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PiyushKohli_0-1690440221009.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52245iDA34C058AF723D6D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PiyushKohli_0-1690440221009.png" alt="PiyushKohli_0-1690440221009.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PiyushKohli_1-1690440347104.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52246i06FDC55E5D5E11CB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PiyushKohli_1-1690440347104.png" alt="PiyushKohli_1-1690440347104.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: This is not recommended, however to see the behavior as shared above, you may test in your test or UAT endpoint before enforcing this to production endpoints.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jul 2023 06:47:48 GMT</pubDate>
    <dc:creator>PiyushKohli</dc:creator>
    <dc:date>2023-07-27T06:47:48Z</dc:date>
    <item>
      <title>How to use BIOC to block specific domains?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-use-bioc-to-block-specific-domains/m-p/551260#M4832</link>
      <description>&lt;P&gt;Dear community,&lt;/P&gt;
&lt;P&gt;I would like to block connections to specific domains using BIOC, &lt;BR /&gt;but I found that the "&lt;STRONG&gt;Add to restrictions profile&lt;/STRONG&gt;" button is missing when right-clicking on a BIOC rule. &lt;BR /&gt;Why is there no such button? Alternatively, is there any way to block specific domains using XDR?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 05:02:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-use-bioc-to-block-specific-domains/m-p/551260#M4832</guid>
      <dc:creator>Chilla</dc:creator>
      <dc:date>2023-07-27T05:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to use BIOC to block specific domains?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-use-bioc-to-block-specific-domains/m-p/551273#M4833</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/251009"&gt;@Chilla&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on your above use case where you want to&amp;nbsp;&lt;SPAN&gt;block specific domains using XDR using BIOC and&amp;nbsp;"&lt;STRONG&gt;Add to restrictions profile&lt;/STRONG&gt;"&amp;nbsp;. Would like to share by using BIOC/BTP this will block/prevent your browser process action as result of which this rule might kill/crash the browser process which could be risky and you might have to reinstall the application again.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In your use case since you want to block specific domains if you are using Palo Alto firewall you may leverage or setup EDL (External Dynamic List) using which you may block the domain and IP.&amp;nbsp;&lt;BR /&gt;Ref: &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-External-Dynamic-Lists" target="_self"&gt;Manage External Dynamic Lists&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-it-possible-to-block-ioc-from-cortex-xdr/td-p/511727" target="_self"&gt;LC Post&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;However, in case you still want to test using BIOC by adding to restriction&amp;nbsp;profile to block specific domain you may create BIOC like this. Update your domain as required, the one in screenshot is for reference only.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PiyushKohli_0-1690440221009.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52245iDA34C058AF723D6D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PiyushKohli_0-1690440221009.png" alt="PiyushKohli_0-1690440221009.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PiyushKohli_1-1690440347104.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52246i06FDC55E5D5E11CB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PiyushKohli_1-1690440347104.png" alt="PiyushKohli_1-1690440347104.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: This is not recommended, however to see the behavior as shared above, you may test in your test or UAT endpoint before enforcing this to production endpoints.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 06:47:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-use-bioc-to-block-specific-domains/m-p/551273#M4833</guid>
      <dc:creator>PiyushKohli</dc:creator>
      <dc:date>2023-07-27T06:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to use BIOC to block specific domains?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-use-bioc-to-block-specific-domains/m-p/551279#M4836</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/251009"&gt;@Chilla&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;You can refer to the discussion on the same lines which mentions the same:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-blocking/m-p/550103#M4801" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-blocking/m-p/550103#M4801&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;URL filtering is a Layer 7 mechanism and Cortex operates on Layer 3. For IPs we can suggest using Cortex XDR host firewalls.&lt;/P&gt;
&lt;P&gt;For URLs, there is no mechanism as such to block the URL.&lt;/P&gt;
&lt;P&gt;The method for BIOC rules is regressive and as BIOC is meant to terminate process events and not network events. However, to create BIOC rules for incoming, outgoing and failed network connections(do not add the raw packets), and then add the domains to the list. Once created, you can add the BIOC to restrictions profiles.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please note, we work on process instances termination and not network termination. Hence the above mentioned step is regressive as any network connection made using browsers for the URL will kill the browser itself and not just the network connection. As a result, all other browser tabs will also shutdown. As a result, this is can be done for 1 or 2 URLs but not a very recommended action. It is recommended to setup a firewall configuration for URL filtering.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 07:27:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-use-bioc-to-block-specific-domains/m-p/551279#M4836</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-07-27T07:27:59Z</dc:date>
    </item>
  </channel>
</rss>

