<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hashes of the attachment from the o365 log in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hashes-of-the-attachment-from-the-o365-log/m-p/558425#M5170</link>
    <description>&lt;P&gt;Dear community,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I've been evaluating the benefits of ingesting o365 logs so far. Seeking those who have the mentioned logs ingested into Cortex XDR -&lt;/P&gt;
&lt;P&gt;does Cortex XDR review and raise alert using the hashes of the attachment if the attachment is a malware?&lt;BR /&gt;&lt;BR /&gt;Besides, what are the useful data / alert that you think it helped your organization in terms of day-to-day operation/investigation?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;BR /&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 18 Sep 2023 19:22:33 GMT</pubDate>
    <dc:creator>Antony_Chan</dc:creator>
    <dc:date>2023-09-18T19:22:33Z</dc:date>
    <item>
      <title>Hashes of the attachment from the o365 log</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hashes-of-the-attachment-from-the-o365-log/m-p/558425#M5170</link>
      <description>&lt;P&gt;Dear community,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I've been evaluating the benefits of ingesting o365 logs so far. Seeking those who have the mentioned logs ingested into Cortex XDR -&lt;/P&gt;
&lt;P&gt;does Cortex XDR review and raise alert using the hashes of the attachment if the attachment is a malware?&lt;BR /&gt;&lt;BR /&gt;Besides, what are the useful data / alert that you think it helped your organization in terms of day-to-day operation/investigation?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;BR /&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 19:22:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hashes-of-the-attachment-from-the-o365-log/m-p/558425#M5170</guid>
      <dc:creator>Antony_Chan</dc:creator>
      <dc:date>2023-09-18T19:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: Hashes of the attachment from the o365 log</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hashes-of-the-attachment-from-the-o365-log/m-p/558508#M5173</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/202190"&gt;@Antony_Chan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on Live Community!&lt;/P&gt;
&lt;P&gt;XDR collect following data from O365 emails.&lt;/P&gt;
&lt;UL class="itemizedlist"&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;All message details except the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class="computeroutput hljs language-css"&gt;&lt;SPAN class="hljs-selector-tag"&gt;body&lt;/SPAN&gt;&lt;/CODE&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class="computeroutput hljs language-undefined"&gt;bodyPreview&lt;/CODE&gt;, and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class="computeroutput hljs language-undefined"&gt;subject&lt;/CODE&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;Attachment details include file name, file type, file hash, size, and id.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Based on above data Cortex XDR raise alerts&amp;nbsp;&lt;SPAN&gt;(Analytics, IOC, BIOC, and Correlation Rules). So if an attachment hash is listed under IOC/BIOC, XDR is going to raise an alert.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regarding useful data/alerts, use case vary from organisation to organisation. XDR collects lot of data like Azure AD logs, exchange logs, DLP etc. Based on these logs you can build use cases. Please refer below documentation for details on ingesting Microsoft O365 logs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Ingest-Logs-from-Microsoft-Office-365" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Ingest-Logs-from-Microsoft-Office-365&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 08:26:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/hashes-of-the-attachment-from-the-o365-log/m-p/558508#M5173</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2023-09-19T08:26:49Z</dc:date>
    </item>
  </channel>
</rss>

