<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block md5 hashes in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-md5-hashes/m-p/389283#M578</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/47142"&gt;@dfalcon&lt;/a&gt;&amp;nbsp;Still looking for this but I wanted to ask here also.&amp;nbsp; Is it then possible to change the Alert Severity of the Alert Name = "Administrative Hash Exception" from LOW (which it appears to default to now) to Medium, so that an INCIDENT is created.&amp;nbsp; Right now it will BLOCK but no Incident is created, as its LOW Severity alert.&lt;/P&gt;</description>
    <pubDate>Fri, 05 Mar 2021 03:47:10 GMT</pubDate>
    <dc:creator>KRisselada</dc:creator>
    <dc:date>2021-03-05T03:47:10Z</dc:date>
    <item>
      <title>Block md5 hashes</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-md5-hashes/m-p/335238#M186</link>
      <description>&lt;P&gt;Dear team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is it possible to block IOC based md5 hashes in cortex xdr?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 09:17:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-md5-hashes/m-p/335238#M186</guid>
      <dc:creator>Marsooq-Akkaradathil</dc:creator>
      <dc:date>2020-06-25T09:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: Block md5 hashes</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-md5-hashes/m-p/338682#M196</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133144"&gt;@Marsooq-Akkaradathil&lt;/a&gt;&amp;nbsp;-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes.&amp;nbsp; Go to Response &amp;gt; Action Center &amp;gt; Blacklist &amp;gt; New Action.&amp;nbsp; From there either enter the MD5 entry or import a list of them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dfalcon_0-1594823306787.png" style="width: 858px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26790i840E8255D07B1CB4/image-dimensions/858x429/is-moderation-mode/true?v=v2" width="858" height="429" role="button" title="dfalcon_0-1594823306787.png" alt="dfalcon_0-1594823306787.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 14:29:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-md5-hashes/m-p/338682#M196</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-07-15T14:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: Block md5 hashes</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-md5-hashes/m-p/389283#M578</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/47142"&gt;@dfalcon&lt;/a&gt;&amp;nbsp;Still looking for this but I wanted to ask here also.&amp;nbsp; Is it then possible to change the Alert Severity of the Alert Name = "Administrative Hash Exception" from LOW (which it appears to default to now) to Medium, so that an INCIDENT is created.&amp;nbsp; Right now it will BLOCK but no Incident is created, as its LOW Severity alert.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 03:47:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-md5-hashes/m-p/389283#M578</guid>
      <dc:creator>KRisselada</dc:creator>
      <dc:date>2021-03-05T03:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: Block md5 hashes</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-md5-hashes/m-p/390123#M585</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/166820"&gt;@KRisselada&lt;/a&gt;-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the alert, what is listed as the source?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 21:44:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-md5-hashes/m-p/390123#M585</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2021-03-09T21:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: Block md5 hashes</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-md5-hashes/m-p/390130#M586</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/47142"&gt;@dfalcon&lt;/a&gt;&amp;nbsp;its Alert Source = XDR Agent, Alert Name = Administrative Hash Exception&lt;/P&gt;&lt;P&gt;Its set as Low, with regard to Severity, I wondered if I could adjust the Sev from the default Low, to say Medium. I wondered if Scoring Rules (within Incident Management) might do that, but does not seem to be, or I am not doing it correctly.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 21:51:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-md5-hashes/m-p/390130#M586</guid>
      <dc:creator>KRisselada</dc:creator>
      <dc:date>2021-03-09T21:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: Block md5 hashes</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-md5-hashes/m-p/390473#M594</link>
      <description>&lt;P&gt;actually SHA256 only. there is no provision for providing and MD5 hash that we can see. And even if we try to add an MD5, the system doesn't accept any MD5 hashes&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 08:46:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-md5-hashes/m-p/390473#M594</guid>
      <dc:creator>QDSupportUser</dc:creator>
      <dc:date>2021-03-11T08:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: Block md5 hashes</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-md5-hashes/m-p/390803#M604</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/39193"&gt;@QDSupportUser&lt;/a&gt;&amp;nbsp;actually I didn't come up with the subject line that indicated MD5.&amp;nbsp; But the goal (via SHA256) was close.&amp;nbsp; Essentially was looking to have an Incident created from an alert named&amp;nbsp;&lt;SPAN&gt;Administrative Hash Exception, which seems to be by default set to LOW.&amp;nbsp; I was looking to make that an Incident.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;So to restate here was looking to:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;add Hash to Block list, have Alert generated (done, this works&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Have that alert create an Incident (does not do that now &lt;span class="lia-unicode-emoji" title=":thumbs_down:"&gt;👎&lt;/span&gt;, I believe because the Severity of the alert is set to Low)&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;I also don't wish to have EVERY Low Sev alert become an Incident, just the "Administrative Hash Exception" alerts&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Hope that helps.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 00:51:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/block-md5-hashes/m-p/390803#M604</guid>
      <dc:creator>KRisselada</dc:creator>
      <dc:date>2021-03-12T00:51:41Z</dc:date>
    </item>
  </channel>
</rss>

