<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to influence the XDR Analytics BIOC and the backend engine in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-influence-the-xdr-analytics-bioc-and-the-backend-engine/m-p/616218#M7407</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The XDR Analytics BIOC alerts are created based on for example rare events that occur in your environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to influence the backend system for example:&lt;/P&gt;
&lt;P&gt;If I add a hash to the allow list will that make the process trusted and not create alerts for it even if its rare?&lt;BR /&gt;&lt;BR /&gt;My question is how can these types of alerts be influenced rather than just creating exceptions.&lt;/P&gt;</description>
    <pubDate>Wed, 06 Nov 2024 09:14:53 GMT</pubDate>
    <dc:creator>AvesterFahimipour</dc:creator>
    <dc:date>2024-11-06T09:14:53Z</dc:date>
    <item>
      <title>How to influence the XDR Analytics BIOC and the backend engine</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-influence-the-xdr-analytics-bioc-and-the-backend-engine/m-p/616218#M7407</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The XDR Analytics BIOC alerts are created based on for example rare events that occur in your environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to influence the backend system for example:&lt;/P&gt;
&lt;P&gt;If I add a hash to the allow list will that make the process trusted and not create alerts for it even if its rare?&lt;BR /&gt;&lt;BR /&gt;My question is how can these types of alerts be influenced rather than just creating exceptions.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 09:14:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-influence-the-xdr-analytics-bioc-and-the-backend-engine/m-p/616218#M7407</guid>
      <dc:creator>AvesterFahimipour</dc:creator>
      <dc:date>2024-11-06T09:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to influence the XDR Analytics BIOC and the backend engine</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-influence-the-xdr-analytics-bioc-and-the-backend-engine/m-p/616226#M7408</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/325593"&gt;@AvesterFahimipour&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for your query on LC!&lt;BR /&gt;&lt;BR /&gt;For this, I think we need more understanding on how different modules and protection flow work.&lt;BR /&gt;Creating an exception for a process based on hash will exempt the process in the initial stages of execution however if the sam process is ben caught by other modules like BTP or Analytics or BIOC with suspicious activity then the action will be terminated or reported based on the module.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class="italic"&gt;Analytics behavioral indicators of compromise (BIOC)s&lt;/SPAN&gt;&lt;SPAN&gt;. In contrast to standard Analytics alerts, Analytics BIOCs (&lt;/SPAN&gt;&lt;SPAN class="italic"&gt;ABIOCs&lt;/SPAN&gt;&lt;SPAN&gt;)—indicate a single event of suspicious behavior with an identified chain of causality. To identify the context and chain of causality, ABIOCs leverage user, endpoint, and network profiles. The profile is generated by the Analytics Engine and can be based on a simple statistical profile or a more complex machine-learning profile.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="phrase"&gt;Cortex XDR&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;tailors each ABIOC to your specific environment after analyzing your logs and data sources and continually tunes and delivers new ABIOCs with content updates.&lt;/SPAN&gt;&lt;BR /&gt;Ref -&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics-Concepts?section=UUID-7a3f4a9a-7a44-5523-ab5c-5310800e72af_UUID-c5195632-e53d-23ab-27f0-c8cda46d9dcc" target="_blank" rel="noopener"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics-Concepts?section=UUID-7a3f4a9a-7a44-5523-ab5c-5310800e72af_UUID-c5195632-e53d-23ab-27f0-c8cda46d9dcc&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 10:30:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-influence-the-xdr-analytics-bioc-and-the-backend-engine/m-p/616226#M7408</guid>
      <dc:creator>nar</dc:creator>
      <dc:date>2024-11-06T10:30:44Z</dc:date>
    </item>
  </channel>
</rss>

