<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: About Behavioral Threat Protection (BTP) rules in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/about-behavioral-threat-protection-btp-rules/m-p/401545#M688</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/112774"&gt;@gjenkins&lt;/a&gt;&amp;nbsp;Any idea if the alert repo will be made public at a future state? Thinking it would save time and effort for engineers attempting to work through false positives.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Apr 2021 16:51:11 GMT</pubDate>
    <dc:creator>efriend</dc:creator>
    <dc:date>2021-04-23T16:51:11Z</dc:date>
    <item>
      <title>About Behavioral Threat Protection (BTP) rules</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/about-behavioral-threat-protection-btp-rules/m-p/395977#M649</link>
      <description>&lt;P&gt;Hi Everyone：&lt;/P&gt;&lt;P&gt;Does anyone know where I can find Behavioral Threat Protection (BTP) rules?&lt;BR /&gt;For example, a behavioral threat is detected (rule: pp.epm_for_malware_behavior_j01)&lt;BR /&gt;or Behavior threat detected (rule: bioc.pp.ransom_prevention_final)&lt;/P&gt;&lt;P&gt;What do these two rules mean?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 09:16:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/about-behavioral-threat-protection-btp-rules/m-p/395977#M649</guid>
      <dc:creator>RichardChou</dc:creator>
      <dc:date>2021-04-06T09:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: About Behavioral Threat Protection (BTP) rules</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/about-behavioral-threat-protection-btp-rules/m-p/396058#M653</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10081"&gt;@RichardChou&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The protection rule database is not publicly accessible at this time. To get information regarding the rules, why they were triggered, and recommendations on the next steps, please &lt;A href="https://support.paloaltonetworks.com/" target="_self"&gt;open a support case&lt;/A&gt;. They will likely need the Alert data to perform further analysis as well. That can be collected using the following instructions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Steps to collect Alert Data from Cortex XDR Console:&lt;/P&gt;&lt;P&gt;1. Got to the Alerts table.&lt;BR /&gt;2. Right-click on your target alert&lt;BR /&gt;3. Select "Retrieve Additional Data," then "Retrieve alert data."&lt;BR /&gt;3. Navigate to Response &amp;gt; Action Center&lt;BR /&gt;5. Locate the alert data retrieval job that you created.&lt;BR /&gt;6. Right-click on your target job&lt;BR /&gt;7. Select "Additional Data."&lt;BR /&gt;8. Right-click on the resulting action&lt;BR /&gt;9. Select "Download Files."&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 16:29:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/about-behavioral-threat-protection-btp-rules/m-p/396058#M653</guid>
      <dc:creator>gjenkins</dc:creator>
      <dc:date>2021-04-06T16:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: About Behavioral Threat Protection (BTP) rules</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/about-behavioral-threat-protection-btp-rules/m-p/397392#M661</link>
      <description>&lt;P&gt;&lt;FONT color="#000000"&gt;Hi&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;Gjenkins&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;BR /&gt;I understand.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 01:27:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/about-behavioral-threat-protection-btp-rules/m-p/397392#M661</guid>
      <dc:creator>RichardChou</dc:creator>
      <dc:date>2021-04-13T01:27:44Z</dc:date>
    </item>
    <item>
      <title>Re: About Behavioral Threat Protection (BTP) rules</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/about-behavioral-threat-protection-btp-rules/m-p/401545#M688</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/112774"&gt;@gjenkins&lt;/a&gt;&amp;nbsp;Any idea if the alert repo will be made public at a future state? Thinking it would save time and effort for engineers attempting to work through false positives.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 16:51:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/about-behavioral-threat-protection-btp-rules/m-p/401545#M688</guid>
      <dc:creator>efriend</dc:creator>
      <dc:date>2021-04-23T16:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: About Behavioral Threat Protection (BTP) rules</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/about-behavioral-threat-protection-btp-rules/m-p/402035#M691</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179591"&gt;@efriend&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/112774"&gt;@gjenkins&lt;/a&gt;&amp;nbsp;Any idea if the alert repo will be made public at a future state? Thinking it would save time and effort for engineers attempting to work through false positives.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179591"&gt;@efriend&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this moment in time, I'm unaware of it becoming public. As always, if you have a false positive, opening a case with our Support team is the best next step as we would likely need to refine the rules involved. Having the opportunity to do so will improve accuracy, efficiency, and ultimately the protection offered by the Cortex XDR agent.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 21:50:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/about-behavioral-threat-protection-btp-rules/m-p/402035#M691</guid>
      <dc:creator>gjenkins</dc:creator>
      <dc:date>2021-04-26T21:50:46Z</dc:date>
    </item>
  </channel>
</rss>

