<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BIOC Rules for OneDrive File Uploads | Exfiltration in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-rules-for-onedrive-file-uploads-exfiltration/m-p/599093#M7250</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/315565"&gt;@Melvin_Machado&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the severity configured to this custom BIOC rule? Only Medium to Critical alerts will generate an Incident, and if the host generating it is always the same, the alerts should be added to the same Incident.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
    <pubDate>Mon, 30 Sep 2024 14:45:22 GMT</pubDate>
    <dc:creator>jmazzeo</dc:creator>
    <dc:date>2024-09-30T14:45:22Z</dc:date>
    <item>
      <title>BIOC Rules for OneDrive File Uploads | Exfiltration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-rules-for-onedrive-file-uploads-exfiltration/m-p/598967#M7241</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have encountered an issue where some users in my organization are uploading large files (around 100 GB) to their personal OneDrive accounts using public Microsoft domains. Currently, Cortex is allowing these actions without signaling them.&lt;/P&gt;
&lt;P&gt;To address this, I created my own BIOC rules, which are functioning well :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="100%"&gt;preset = network_story&lt;BR /&gt;| filter dst_action_external_hostname in ("*.onedrive.com", "*.onedrive.live.com") and action_total_upload &amp;gt; 1000000&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;However, I'm facing two challenges:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Multiple alerts are being generated, but no Incident (INC) is being created.&lt;/LI&gt;
&lt;LI&gt;How can I consolidate these alerts to generate only one alert (instead of 20) when a user uploads files to OneDrive?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I would appreciate your guidance on resolving these issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 14:51:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-rules-for-onedrive-file-uploads-exfiltration/m-p/598967#M7241</guid>
      <dc:creator>Melvin_Machado</dc:creator>
      <dc:date>2024-09-27T14:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: BIOC Rules for OneDrive File Uploads | Exfiltration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-rules-for-onedrive-file-uploads-exfiltration/m-p/599093#M7250</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/315565"&gt;@Melvin_Machado&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the severity configured to this custom BIOC rule? Only Medium to Critical alerts will generate an Incident, and if the host generating it is always the same, the alerts should be added to the same Incident.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 14:45:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-rules-for-onedrive-file-uploads-exfiltration/m-p/599093#M7250</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-09-30T14:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: BIOC Rules for OneDrive File Uploads | Exfiltration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-rules-for-onedrive-file-uploads-exfiltration/m-p/599158#M7253</link>
      <description>&lt;P&gt;Hello Jmazzeo,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I change the severity to Medium, it creates an incident and merges all the alerts as expected&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;However, I’m facing another issue now. An alert is being generated even when only 4 KB is uploaded.&lt;/P&gt;
&lt;P&gt;I would like the system to trigger an alert only when more than 10 MB is uploaded. Could you help me adjust this setting?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 08:36:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-rules-for-onedrive-file-uploads-exfiltration/m-p/599158#M7253</guid>
      <dc:creator>Melvin_Machado</dc:creator>
      <dc:date>2024-10-01T08:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: BIOC Rules for OneDrive File Uploads | Exfiltration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-rules-for-onedrive-file-uploads-exfiltration/m-p/599164#M7254</link>
      <description>&lt;P&gt;Thank you for your help! I found a solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="100%"&gt;preset = network_story&lt;BR /&gt;| filter dst_action_external_hostname in ("*.onedrive.com", "*.onedrive.live.com")&lt;BR /&gt;| filter action_total_upload &amp;gt; 10485760&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 14:31:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-rules-for-onedrive-file-uploads-exfiltration/m-p/599164#M7254</guid>
      <dc:creator>Melvin_Machado</dc:creator>
      <dc:date>2024-10-18T14:31:42Z</dc:date>
    </item>
    <item>
      <title>Re: BIOC Rules for OneDrive File Uploads | Exfiltration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-rules-for-onedrive-file-uploads-exfiltration/m-p/995761#M7511</link>
      <description>&lt;P&gt;| filter action_total_upload &amp;gt; 80000000 // bit (10 Mo)&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2024 15:25:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-rules-for-onedrive-file-uploads-exfiltration/m-p/995761#M7511</guid>
      <dc:creator>Melvin_Machado</dc:creator>
      <dc:date>2024-11-29T15:25:12Z</dc:date>
    </item>
  </channel>
</rss>

