<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XDR Global BIOC rules in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-global-bioc-rules/m-p/405477#M719</link>
    <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;If Restrictions profile for Windows is default then they don`t directly affect windows endpoints. We must edit and and apply them for getting protection in endpoints. But in Linux it is not same. Even if Restriction profile is default, XDR can generate alert base on global BIOC. I want to know why there are such difference?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Fri, 07 May 2021 13:02:40 GMT</pubDate>
    <dc:creator>OrkanAlibayli</dc:creator>
    <dc:date>2021-05-07T13:02:40Z</dc:date>
    <item>
      <title>XDR Global BIOC rules</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-global-bioc-rules/m-p/405477#M719</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;If Restrictions profile for Windows is default then they don`t directly affect windows endpoints. We must edit and and apply them for getting protection in endpoints. But in Linux it is not same. Even if Restriction profile is default, XDR can generate alert base on global BIOC. I want to know why there are such difference?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2021 13:02:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-global-bioc-rules/m-p/405477#M719</guid>
      <dc:creator>OrkanAlibayli</dc:creator>
      <dc:date>2021-05-07T13:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Global BIOC rules</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-global-bioc-rules/m-p/405965#M726</link>
      <description>&lt;P&gt;Hey Orkan,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure I completely got your question so tell if the following helps with understanding the flow:&lt;/P&gt;&lt;P&gt;Restriction profile allows you to apply custom made BIOC's that upon detection will be prevented by the agent, in case you are using the default profiles then no prevention will take place but the detection will happen if the BIOC rule is configured in your BIOC repository (preconfigured or custom made BIOCs).&lt;/P&gt;&lt;P&gt;BIOC's will trigger detection alerts regarding the fact that no prevention rule configured in the restriction profile, those are 2 different capabilities that can be linked in order to enhance the prevention capabilities.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is that answer you question?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 09:09:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-global-bioc-rules/m-p/405965#M726</guid>
      <dc:creator>mabutbul</dc:creator>
      <dc:date>2021-05-11T09:09:20Z</dc:date>
    </item>
  </channel>
</rss>

