<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XDR Usecase Creation | XDR Rule in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-usecase-creation-xdr-rule/m-p/568449#M5663</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;Mohitparashar,&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Adding an&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://urldefense.com/v3/__https:/docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Working-with-IOCs__;!!Hj9Y_P0nvg!RM5XJWmfHSSYIG7FzznIgsjrjx7OcOZ85n8W85kl3TtzIRm1LrIBqCP6r67pVasvqj0aSZz28xLoCLIQ--TnipdE1bZQcgT4$" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://urldefense.com/v3/__https:/docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Working-with-IOCs__;!!Hj9Y_P0nvg!RM5XJWmfHSSYIG7FzznIgsjrjx7OcOZ85n8W85kl3TtzIRm1LrIBqCP6r67pVasvqj0aSZz28xLoCLIQ--TnipdE1bZQcgT4$&amp;amp;source=gmail&amp;amp;ust=1701878163129000&amp;amp;usg=AOvVaw1hVBWsFf_BdqKOzecPB95V"&gt;&lt;SPAN&gt;IOC&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;is a Detect Only indicator. We recommend that IOCs be added to the firewall policy to block as URL filtering is a Layer 7 mechanism and Cortex operates on Layer 3. I&lt;/SPAN&gt;&lt;SPAN&gt;f you are using a Palo Alto firewall you may leverage the EDL (&lt;/SPAN&gt;&lt;A href="https://urldefense.com/v3/__https:/docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-External-Dynamic-Lists__;!!Hj9Y_P0nvg!RM5XJWmfHSSYIG7FzznIgsjrjx7OcOZ85n8W85kl3TtzIRm1LrIBqCP6r67pVasvqj0aSZz28xLoCLIQ--TnipdE1RLUl17-$" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://urldefense.com/v3/__https:/docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-External-Dynamic-Lists__;!!Hj9Y_P0nvg!RM5XJWmfHSSYIG7FzznIgsjrjx7OcOZ85n8W85kl3TtzIRm1LrIBqCP6r67pVasvqj0aSZz28xLoCLIQ--TnipdE1RLUl17-$&amp;amp;source=gmail&amp;amp;ust=1701878163129000&amp;amp;usg=AOvVaw2y4B7DN5lOkDKVdrMxmIE9"&gt;Manage External Dynamic Lists&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;) to block the domain and IP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For non-network events, you may create a custom BIOC using an XQL query to enable a custom prevention rule then add it to the Restrictions Profile applied to the endpoints as outlined in this video &lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/custom-prevention-rules/ta-p/347271" target="_blank"&gt;Custom Prevention Rules| Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The following describes the event_type values for which you can create a BIOC rule.&lt;/P&gt;
&lt;UL style="font-weight: 400;"&gt;
&lt;LI&gt;FILE—Events relating to file create, write, read, and rename according to the file name and path.&lt;/LI&gt;
&lt;LI&gt;INJECTION—Events related to process injections.&lt;/LI&gt;
&lt;LI&gt;LOAD_IMAGE—Events relating to module IDs of processes.&lt;/LI&gt;
&lt;LI&gt;NETWORK—Events relating to incoming and outgoing network, filed IP addresses, port, host name, and protocol.&lt;/LI&gt;
&lt;LI&gt;PROCESS—Events relating to execution and injection of a process name, hash, path, and CMD.&lt;/LI&gt;
&lt;LI&gt;REGISTRY—Events relating to registry write, rename and delete according to registry path.&lt;/LI&gt;
&lt;LI&gt;STORY—Events relating to a combination of firewall and endpoint logs over the network.&lt;/LI&gt;
&lt;LI&gt;EVENT_LOG—Events relating to Windows event logs and Linux system authentication logs.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Once created, you can add the BIOC to restrictions profiles.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A few caveats...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please note, XDR works on process instances termination and not network termination. For example, any network connection made using browsers for the URL (using a BIOC) will kill the browser itself and not just the network connection. As a result, all other browser tabs will also shut down.&amp;nbsp;Therefore, adding a BIOC for domains/IPs is not a recommended action. It is recommended to set up a firewall configuration for URL filtering.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reference&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://urldefense.com/v3/__https:/docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Create-a-BIOC-Rule__;!!Hj9Y_P0nvg!RM5XJWmfHSSYIG7FzznIgsjrjx7OcOZ85n8W85kl3TtzIRm1LrIBqCP6r67pVasvqj0aSZz28xLoCLIQ--TnipdE1QJl9LT1$" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://urldefense.com/v3/__https:/docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Create-a-BIOC-Rule__;!!Hj9Y_P0nvg!RM5XJWmfHSSYIG7FzznIgsjrjx7OcOZ85n8W85kl3TtzIRm1LrIBqCP6r67pVasvqj0aSZz28xLoCLIQ--TnipdE1QJl9LT1$&amp;amp;source=gmail&amp;amp;ust=1701878163129000&amp;amp;usg=AOvVaw3fkZcj0IDiOLdFVZaY4_iR"&gt;Create a BIOC Rule • Cortex XDR Pro Administrator Guide • Reader • Palo Alto Networks documentation portal&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://urldefense.com/v3/__https:/live.paloaltonetworks.com/t5/cortex-xdr-webinars/threat-hunting-with-xdr/ta-p/392207__;!!Hj9Y_P0nvg!RM5XJWmfHSSYIG7FzznIgsjrjx7OcOZ85n8W85kl3TtzIRm1LrIBqCP6r67pVasvqj0aSZz28xLoCLIQ--TnipdE1W3kNYr8$" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://urldefense.com/v3/__https:/live.paloaltonetworks.com/t5/cortex-xdr-webinars/threat-hunting-with-xdr/ta-p/392207__;!!Hj9Y_P0nvg!RM5XJWmfHSSYIG7FzznIgsjrjx7OcOZ85n8W85kl3TtzIRm1LrIBqCP6r67pVasvqj0aSZz28xLoCLIQ--TnipdE1W3kNYr8$&amp;amp;source=gmail&amp;amp;ust=1701878163129000&amp;amp;usg=AOvVaw1hREZLRDo42VfOipuG1_tj"&gt;Threat Hunting with XDR | Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you found this answer helpful, please select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Tue, 05 Dec 2023 17:02:56 GMT</pubDate>
    <dc:creator>jtalton</dc:creator>
    <dc:date>2023-12-05T17:02:56Z</dc:date>
    <item>
      <title>XDR Usecase Creation | XDR Rule</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-usecase-creation-xdr-rule/m-p/568040#M5657</link>
      <description>&lt;P&gt;We have 3 use cases for which we want to set up 3 rules in XDR, we would like to get your help to identify the best avenue to address them :&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;UC 1 : deploy a rule that &lt;STRONG&gt;DETECT&lt;/STRONG&gt; a behavior or IOC (ex: failed auth, file with specific SHA1...), &lt;STRONG&gt;AND&lt;/STRONG&gt; generate an incident.&lt;/LI&gt;
&lt;LI&gt;UC 2 : deploy a rule that &lt;STRONG&gt;PREVENT/BLOCK&lt;/STRONG&gt; a behavior or IOC (ex: failed auth, file with specific SHA1...), &lt;STRONG&gt;AND&lt;/STRONG&gt; generate an incident.&lt;/LI&gt;
&lt;LI&gt;UC 3 : deploy a rule that &lt;STRONG&gt;PREVENT/BLOCK&lt;/STRONG&gt; a behavior or IOC (ex: failed auth, file with specific SHA1...), &lt;STRONG&gt;WITHOUT&lt;/STRONG&gt; generating an incident.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For each use case, please advise what feature to use (e.g.: BIOC, blocklist, correlation rule) and if a change in the profiles is required, as per your guides and best practices.&lt;BR /&gt;&lt;BR /&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/213839"&gt;@LiveCommunityMemberOD&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 13:15:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-usecase-creation-xdr-rule/m-p/568040#M5657</guid>
      <dc:creator>Mohitparashar</dc:creator>
      <dc:date>2023-12-01T13:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Usecase Creation | XDR Rule</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-usecase-creation-xdr-rule/m-p/568449#M5663</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;Mohitparashar,&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Adding an&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://urldefense.com/v3/__https:/docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Working-with-IOCs__;!!Hj9Y_P0nvg!RM5XJWmfHSSYIG7FzznIgsjrjx7OcOZ85n8W85kl3TtzIRm1LrIBqCP6r67pVasvqj0aSZz28xLoCLIQ--TnipdE1bZQcgT4$" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://urldefense.com/v3/__https:/docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Working-with-IOCs__;!!Hj9Y_P0nvg!RM5XJWmfHSSYIG7FzznIgsjrjx7OcOZ85n8W85kl3TtzIRm1LrIBqCP6r67pVasvqj0aSZz28xLoCLIQ--TnipdE1bZQcgT4$&amp;amp;source=gmail&amp;amp;ust=1701878163129000&amp;amp;usg=AOvVaw1hVBWsFf_BdqKOzecPB95V"&gt;&lt;SPAN&gt;IOC&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;is a Detect Only indicator. We recommend that IOCs be added to the firewall policy to block as URL filtering is a Layer 7 mechanism and Cortex operates on Layer 3. I&lt;/SPAN&gt;&lt;SPAN&gt;f you are using a Palo Alto firewall you may leverage the EDL (&lt;/SPAN&gt;&lt;A href="https://urldefense.com/v3/__https:/docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-External-Dynamic-Lists__;!!Hj9Y_P0nvg!RM5XJWmfHSSYIG7FzznIgsjrjx7OcOZ85n8W85kl3TtzIRm1LrIBqCP6r67pVasvqj0aSZz28xLoCLIQ--TnipdE1RLUl17-$" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://urldefense.com/v3/__https:/docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-External-Dynamic-Lists__;!!Hj9Y_P0nvg!RM5XJWmfHSSYIG7FzznIgsjrjx7OcOZ85n8W85kl3TtzIRm1LrIBqCP6r67pVasvqj0aSZz28xLoCLIQ--TnipdE1RLUl17-$&amp;amp;source=gmail&amp;amp;ust=1701878163129000&amp;amp;usg=AOvVaw2y4B7DN5lOkDKVdrMxmIE9"&gt;Manage External Dynamic Lists&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;) to block the domain and IP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For non-network events, you may create a custom BIOC using an XQL query to enable a custom prevention rule then add it to the Restrictions Profile applied to the endpoints as outlined in this video &lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/custom-prevention-rules/ta-p/347271" target="_blank"&gt;Custom Prevention Rules| Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The following describes the event_type values for which you can create a BIOC rule.&lt;/P&gt;
&lt;UL style="font-weight: 400;"&gt;
&lt;LI&gt;FILE—Events relating to file create, write, read, and rename according to the file name and path.&lt;/LI&gt;
&lt;LI&gt;INJECTION—Events related to process injections.&lt;/LI&gt;
&lt;LI&gt;LOAD_IMAGE—Events relating to module IDs of processes.&lt;/LI&gt;
&lt;LI&gt;NETWORK—Events relating to incoming and outgoing network, filed IP addresses, port, host name, and protocol.&lt;/LI&gt;
&lt;LI&gt;PROCESS—Events relating to execution and injection of a process name, hash, path, and CMD.&lt;/LI&gt;
&lt;LI&gt;REGISTRY—Events relating to registry write, rename and delete according to registry path.&lt;/LI&gt;
&lt;LI&gt;STORY—Events relating to a combination of firewall and endpoint logs over the network.&lt;/LI&gt;
&lt;LI&gt;EVENT_LOG—Events relating to Windows event logs and Linux system authentication logs.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Once created, you can add the BIOC to restrictions profiles.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A few caveats...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please note, XDR works on process instances termination and not network termination. For example, any network connection made using browsers for the URL (using a BIOC) will kill the browser itself and not just the network connection. As a result, all other browser tabs will also shut down.&amp;nbsp;Therefore, adding a BIOC for domains/IPs is not a recommended action. It is recommended to set up a firewall configuration for URL filtering.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reference&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://urldefense.com/v3/__https:/docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Create-a-BIOC-Rule__;!!Hj9Y_P0nvg!RM5XJWmfHSSYIG7FzznIgsjrjx7OcOZ85n8W85kl3TtzIRm1LrIBqCP6r67pVasvqj0aSZz28xLoCLIQ--TnipdE1QJl9LT1$" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://urldefense.com/v3/__https:/docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Create-a-BIOC-Rule__;!!Hj9Y_P0nvg!RM5XJWmfHSSYIG7FzznIgsjrjx7OcOZ85n8W85kl3TtzIRm1LrIBqCP6r67pVasvqj0aSZz28xLoCLIQ--TnipdE1QJl9LT1$&amp;amp;source=gmail&amp;amp;ust=1701878163129000&amp;amp;usg=AOvVaw3fkZcj0IDiOLdFVZaY4_iR"&gt;Create a BIOC Rule • Cortex XDR Pro Administrator Guide • Reader • Palo Alto Networks documentation portal&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://urldefense.com/v3/__https:/live.paloaltonetworks.com/t5/cortex-xdr-webinars/threat-hunting-with-xdr/ta-p/392207__;!!Hj9Y_P0nvg!RM5XJWmfHSSYIG7FzznIgsjrjx7OcOZ85n8W85kl3TtzIRm1LrIBqCP6r67pVasvqj0aSZz28xLoCLIQ--TnipdE1W3kNYr8$" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://urldefense.com/v3/__https:/live.paloaltonetworks.com/t5/cortex-xdr-webinars/threat-hunting-with-xdr/ta-p/392207__;!!Hj9Y_P0nvg!RM5XJWmfHSSYIG7FzznIgsjrjx7OcOZ85n8W85kl3TtzIRm1LrIBqCP6r67pVasvqj0aSZz28xLoCLIQ--TnipdE1W3kNYr8$&amp;amp;source=gmail&amp;amp;ust=1701878163129000&amp;amp;usg=AOvVaw1hREZLRDo42VfOipuG1_tj"&gt;Threat Hunting with XDR | Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you found this answer helpful, please select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 17:02:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-usecase-creation-xdr-rule/m-p/568449#M5663</guid>
      <dc:creator>jtalton</dc:creator>
      <dc:date>2023-12-05T17:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Usecase Creation | XDR Rule</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-usecase-creation-xdr-rule/m-p/568467#M5666</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203673"&gt;@jtalton&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My access to the video resource is denied.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/shaolin-beta-articles/video-tutorial-custom-prevention-rules/ta-p/341971" target="_blank"&gt;https://live.paloaltonetworks.com/t5/shaolin-beta-articles/video-tutorial-custom-prevention-rules/ta-p/341971&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please help me with how to access and why it is getting denied?&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Mohit&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 16:58:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-usecase-creation-xdr-rule/m-p/568467#M5666</guid>
      <dc:creator>Mohitparashar</dc:creator>
      <dc:date>2023-12-05T16:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Usecase Creation | XDR Rule</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-usecase-creation-xdr-rule/m-p/568469#M5667</link>
      <description>&lt;P&gt;Sorry this is the correct link&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/custom-prevention-rules/ta-p/347271" target="_blank"&gt;Custom Prevention Rules| Palo Alto Networks&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 17:02:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-usecase-creation-xdr-rule/m-p/568469#M5667</guid>
      <dc:creator>jtalton</dc:creator>
      <dc:date>2023-12-05T17:02:19Z</dc:date>
    </item>
  </channel>
</rss>

