<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL &amp;amp; Application level blocking possibilities in Cortex XDR. in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-amp-application-level-blocking-possibilities-in-cortex-xdr/m-p/581675#M6405</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/322192"&gt;@Aneesh&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks for reaching out on LiveCommunity!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For URL blocking you can take the help of EDL blocking:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-External-Dynamic-Lists" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-External-Dynamic-Lists&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For point 2 and three you can&amp;nbsp;configure a custom prevention rule for a BIOC Process event, apply it to the Restrictions profile with an action mode set to Block.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Create-a-BIOC-Rule" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Create-a-BIOC-Rule&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Mar 2024 07:53:52 GMT</pubDate>
    <dc:creator>aspatil</dc:creator>
    <dc:date>2024-03-26T07:53:52Z</dc:date>
    <item>
      <title>URL &amp; Application level blocking possibilities in Cortex XDR.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-amp-application-level-blocking-possibilities-in-cortex-xdr/m-p/581317#M6388</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope you all are doing good.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone help me to understand the possibilities of url and application-level blocking in XDR?&lt;/P&gt;
&lt;P&gt;Following are my scenarios,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Blocking of URLs in XDR.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Blocking of execution/installation of specific applications in XDR.&lt;/P&gt;
&lt;P&gt;3. Blocking of applications running without installation.(eg. anydesk application running directly by double clicking the .exe file).&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Support will be very much appreciated.&lt;/P&gt;
&lt;P&gt;Aneesh&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 06:04:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-amp-application-level-blocking-possibilities-in-cortex-xdr/m-p/581317#M6388</guid>
      <dc:creator>Aneesh</dc:creator>
      <dc:date>2024-03-22T06:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: URL &amp; Application level blocking possibilities in Cortex XDR.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-amp-application-level-blocking-possibilities-in-cortex-xdr/m-p/581675#M6405</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/322192"&gt;@Aneesh&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks for reaching out on LiveCommunity!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For URL blocking you can take the help of EDL blocking:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-External-Dynamic-Lists" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-External-Dynamic-Lists&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For point 2 and three you can&amp;nbsp;configure a custom prevention rule for a BIOC Process event, apply it to the Restrictions profile with an action mode set to Block.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Create-a-BIOC-Rule" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Create-a-BIOC-Rule&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 07:53:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-amp-application-level-blocking-possibilities-in-cortex-xdr/m-p/581675#M6405</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-03-26T07:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: URL &amp; Application level blocking possibilities in Cortex XDR.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-amp-application-level-blocking-possibilities-in-cortex-xdr/m-p/998295#M7577</link>
      <description>&lt;P&gt;This is just pointing a firewall to an EDL that's managed in the cortex tenant. What if the user takes their laptop home and is no longer behind the corporate firewall? Is there a method of blocking access to a URL by cortex XDR itself?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 16:39:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-amp-application-level-blocking-possibilities-in-cortex-xdr/m-p/998295#M7577</guid>
      <dc:creator>ycgmis</dc:creator>
      <dc:date>2024-12-13T16:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: URL &amp; Application level blocking possibilities in Cortex XDR.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-amp-application-level-blocking-possibilities-in-cortex-xdr/m-p/998381#M7584</link>
      <description>&lt;P&gt;Indeed, EDL can't be helpful without firewall.&amp;nbsp; All the mentioned restrictions can be achieved using BIOC rules assigned to restriction profile.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example of BIOC for blocking URL:&lt;/P&gt;
&lt;P&gt;dataset = xdr_data&lt;/P&gt;
&lt;P&gt;| filter event_type = ENUM.NETWORK and action_external_hostname in ("facebook.com", "instagram.com", "linkedin.com", "x.com")&lt;/P&gt;</description>
      <pubDate>Sat, 14 Dec 2024 23:35:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-amp-application-level-blocking-possibilities-in-cortex-xdr/m-p/998381#M7584</guid>
      <dc:creator>maximk</dc:creator>
      <dc:date>2024-12-14T23:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: URL &amp; Application level blocking possibilities in Cortex XDR.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-amp-application-level-blocking-possibilities-in-cortex-xdr/m-p/1219287#M7840</link>
      <description>&lt;P&gt;Unfortunately for some reason the proposed BIOC can't be &lt;SPAN&gt;assigned to restriction profile.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 11:38:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-amp-application-level-blocking-possibilities-in-cortex-xdr/m-p/1219287#M7840</guid>
      <dc:creator>maximk</dc:creator>
      <dc:date>2025-02-04T11:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: URL &amp; Application level blocking possibilities in Cortex XDR.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-amp-application-level-blocking-possibilities-in-cortex-xdr/m-p/1219397#M7842</link>
      <description>&lt;P&gt;To configure a BIOC rule as a prevention rule:&lt;/P&gt;
&lt;DIV class="procedure"&gt;
&lt;OL class="procedure" type="1"&gt;
&lt;LI class="step"&gt;
&lt;P class="cmd"&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guilabel"&gt;BIOC Rule&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;table, from the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="guilabel"&gt;Source&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field, filter and locate a user-defined rule you want to apply as a custom prevention rule. You can only apply a BIOC rule that you created either from scratch or a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="phrase"&gt;Cortex XDR&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;global rule template that meets the following criteria.&lt;/P&gt;
&lt;DIV class="itemizedlist"&gt;
&lt;UL class="itemizedlist"&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;The user-defined BIOC rule does not include the following field configurations.&lt;/P&gt;
&lt;DIV class="itemizedlist"&gt;
&lt;UL class="itemizedlist"&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;All Events—Host Name&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;File Event—Device Type, Device Serial Number&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;Process Event—Device Type, Device Serial Number&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;Network Event—Country, Raw Packet&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;BIOC rules with OS scope definitions must align with the Restrictions profile OS.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="listitem"&gt;
&lt;P&gt;When defining the Process criteria for a user-defined BIOC rule event type, you can select to run only on actor, causality, and OS actor on Windows, and causality and OS actor on Linux and Mac.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the doc:&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Create-a-BIOC-rule" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Create-a-BIOC-rule&lt;/A&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 04 Feb 2025 19:42:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/url-amp-application-level-blocking-possibilities-in-cortex-xdr/m-p/1219397#M7842</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2025-02-04T19:42:09Z</dc:date>
    </item>
  </channel>
</rss>

