<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best way to restrict software by digital signer in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-restrict-software-by-digital-signer/m-p/584363#M6544</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/254463"&gt;@Jason-Voice1&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your approach using a custom BIOC is the correct one. The following screenshot is an example I have in our Lab, to block a signer execution and installation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1713551076348.png" style="width: 630px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59168i6AE7BAD7A5142A5E/image-dimensions/630x480/is-moderation-mode/true?v=v2" width="630" height="480" role="button" title="jmazzeo_0-1713551076348.png" alt="jmazzeo_0-1713551076348.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Apr 2024 18:25:14 GMT</pubDate>
    <dc:creator>jmazzeo</dc:creator>
    <dc:date>2024-04-19T18:25:14Z</dc:date>
    <item>
      <title>Best way to restrict software by digital signer</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-restrict-software-by-digital-signer/m-p/584308#M6540</link>
      <description>&lt;P&gt;hey guys, i'm not clear how to block the running (installing) of certain software using XDR by restricting by digital signer.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Is it possible to cerate a BIOC and apply to a restricted profile? If not, what would you say is the best way to go about this?&lt;BR /&gt;&lt;BR /&gt;Our scenario is we'd like to block the use / installation of a certain piece of software,&amp;nbsp;&lt;SPAN&gt;and I'm thinking that some sort of digital signer restriction might do this.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks for any help in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 07:48:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-restrict-software-by-digital-signer/m-p/584308#M6540</guid>
      <dc:creator>Jason-Voice1</dc:creator>
      <dc:date>2024-04-19T07:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Best way to restrict software by digital signer</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-restrict-software-by-digital-signer/m-p/584363#M6544</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/254463"&gt;@Jason-Voice1&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your approach using a custom BIOC is the correct one. The following screenshot is an example I have in our Lab, to block a signer execution and installation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1713551076348.png" style="width: 630px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59168i6AE7BAD7A5142A5E/image-dimensions/630x480/is-moderation-mode/true?v=v2" width="630" height="480" role="button" title="jmazzeo_0-1713551076348.png" alt="jmazzeo_0-1713551076348.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 18:25:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-restrict-software-by-digital-signer/m-p/584363#M6544</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-04-19T18:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: Best way to restrict software by digital signer</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-restrict-software-by-digital-signer/m-p/650587#M7469</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class="UserName lia-user-name lia-user-rank-L0-Member lia-component-message-view-widget-author-username"&gt;&lt;A id="link_10" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/254463" target="_self" aria-label="View Profile of Jason-Voice1"&gt;&lt;SPAN class=""&gt;Jason-Voice1&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L0-Member lia-component-message-view-widget-author-username"&gt;You have to use XQL query based on singature. For example:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L0-Member lia-component-message-view-widget-author-username"&gt;dataset = xdr_data |&lt;BR /&gt;filter event_type=ENUM.PROCESS | &lt;BR /&gt;filter (causality_actor_process_signature_vendor contains """Brave Software, Inc.""") &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Nov 2024 07:32:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/best-way-to-restrict-software-by-digital-signer/m-p/650587#M7469</guid>
      <dc:creator>E.Jafarov</dc:creator>
      <dc:date>2024-11-23T07:32:15Z</dc:date>
    </item>
  </channel>
</rss>

