<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BIOC Block executables based field &amp;quot;Process_File_Info&amp;quot; in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-block-executables-based-field-quot-process-file-info-quot/m-p/650521#M7468</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&lt;A id="link_10" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/270645" target="_self" aria-label="View Profile of agirones"&gt;&lt;SPAN class=""&gt;agirones&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;You could search due to vendor signature, for example:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;dataset = xdr_data |&lt;BR /&gt;filter event_type=ENUM.PROCESS | &lt;BR /&gt;filter (causality_actor_process_signature_vendor contains """Brave Software, Inc.""")&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 23 Nov 2024 06:10:53 GMT</pubDate>
    <dc:creator>E.Jafarov</dc:creator>
    <dc:date>2024-11-23T06:10:53Z</dc:date>
    <item>
      <title>BIOC Block executables based field "Process_File_Info"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-block-executables-based-field-quot-process-file-info-quot/m-p/585040#M6599</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I would like to know if any of you have struggled with support and technical cases with the need I show below.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I would like to know what you can tell me or give me your opinion of blocking executables based on static metadata using the “Process_File_Info” field in the BIOC.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;My intention is to block executables and not based on the executable name, because based on the executable name the BIOC stops matching if this executable name is modified.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Any suggestions?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Regards!&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 09:05:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-block-executables-based-field-quot-process-file-info-quot/m-p/585040#M6599</guid>
      <dc:creator>agirones</dc:creator>
      <dc:date>2024-04-26T09:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: BIOC Block executables based field "Process_File_Info"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-block-executables-based-field-quot-process-file-info-quot/m-p/585166#M6608</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello everyone,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I may not have explained myself in the best possible way, because this post has had 102 hits and no response.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;So, the behavior we want to detect or restrict, is the use of an executable that we do not want to allow in our environment.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;1. We do not want the BIOC to be based on the name of the executable because this name can be modified. 2.&lt;/P&gt;
&lt;P&gt;2. We do not want the BIOC to be based on Hash, because an update or modification of the executable would not match with this hash.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I would appreciate if anyone has any suggestions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;About:&lt;BR /&gt;There is the field "Process_File_Info", which Palo Alto communicates:&lt;/P&gt;
&lt;P&gt;PROCESS_FILE_INFO-Metadata of the process file, including file property details, file entropy, company name, encryption status, and version number.&lt;/P&gt;
&lt;P&gt;But I cannot save the BIOC without getting the WILDCARD error.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks and best regards!&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 06:29:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-block-executables-based-field-quot-process-file-info-quot/m-p/585166#M6608</guid>
      <dc:creator>agirones</dc:creator>
      <dc:date>2024-04-29T06:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: BIOC Block executables based field "Process_File_Info"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-block-executables-based-field-quot-process-file-info-quot/m-p/650521#M7468</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&lt;A id="link_10" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/270645" target="_self" aria-label="View Profile of agirones"&gt;&lt;SPAN class=""&gt;agirones&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;You could search due to vendor signature, for example:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;dataset = xdr_data |&lt;BR /&gt;filter event_type=ENUM.PROCESS | &lt;BR /&gt;filter (causality_actor_process_signature_vendor contains """Brave Software, Inc.""")&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Nov 2024 06:10:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-block-executables-based-field-quot-process-file-info-quot/m-p/650521#M7468</guid>
      <dc:creator>E.Jafarov</dc:creator>
      <dc:date>2024-11-23T06:10:53Z</dc:date>
    </item>
  </channel>
</rss>

