<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Monitor bitlocker in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/monitor-bitlocker/m-p/587990#M6735</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am checking if it is possible, to monitor from cortex when BitLocker is enabled on the computer, via a BIOC?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards.&lt;/P&gt;</description>
    <pubDate>Mon, 27 May 2024 08:10:18 GMT</pubDate>
    <dc:creator>JPrezHidalgo</dc:creator>
    <dc:date>2024-05-27T08:10:18Z</dc:date>
    <item>
      <title>Monitor bitlocker</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/monitor-bitlocker/m-p/587990#M6735</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am checking if it is possible, to monitor from cortex when BitLocker is enabled on the computer, via a BIOC?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 08:10:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/monitor-bitlocker/m-p/587990#M6735</guid>
      <dc:creator>JPrezHidalgo</dc:creator>
      <dc:date>2024-05-27T08:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor bitlocker</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/monitor-bitlocker/m-p/587992#M6737</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1039296089"&gt;@JPrezHidalgo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out on Live community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Behavioral indicators of compromise (BIOCs) enable you to alert and respond to behaviors—tactics, techniques, and procedures. Instead of hashes and other traditional indicators of compromise, BIOC rules detect behavior such as is related to processes, registry, files, and network activity.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you want to monitor the encryption status on the machines, you can refer to below query:&lt;BR /&gt;dataset = endpoints &lt;BR /&gt;|fields endpoint_name , endpoint_id , operating_system , encryption_status &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create Dashboard or use correlation rule as per your need.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution".&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 08:26:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/monitor-bitlocker/m-p/587992#M6737</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-05-27T08:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor bitlocker</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/monitor-bitlocker/m-p/587994#M6738</link>
      <description>&lt;P&gt;In this case, we do not need to see the encryption status (if applied by Cortex XDR), but to see when the bitlocker goes from inactive to active.&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 08:58:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/monitor-bitlocker/m-p/587994#M6738</guid>
      <dc:creator>JPrezHidalgo</dc:creator>
      <dc:date>2024-05-27T08:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor bitlocker</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/monitor-bitlocker/m-p/588336#M6763</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1039296089"&gt;@JPrezHidalgo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The idle way is to run manage-bde -status. However, if you want to be notified, I have found two ways here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. To look for the event id's when encryption starts and completes and create a correlation rule and get alerted.&lt;/P&gt;
&lt;P&gt;2. Check with Microsoft which registries can be verified to ensure that encryption status changes and create the BIOC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or you can get the report in every specific time frame and ingest back into XDR and create the correlation rule. Please ensure you have pro per GB license for it.&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 05:42:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/monitor-bitlocker/m-p/588336#M6763</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-05-30T05:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor bitlocker</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/monitor-bitlocker/m-p/588365#M6770</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you very much for the answer, you are helping me enormously. The question is that the idea I had was to do what you said in point number 1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I can not identify in the telemetry the event that allows me to perform the correlation rule to warn us.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you very much for your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 08:03:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/monitor-bitlocker/m-p/588365#M6770</guid>
      <dc:creator>JPrezHidalgo</dc:creator>
      <dc:date>2024-05-30T08:03:47Z</dc:date>
    </item>
  </channel>
</rss>

