<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTP Transfer Custom BIOC in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ftp-transfer-custom-bioc/m-p/1086033#M7751</link>
    <description>&lt;P&gt;Hello Palo Alto LiveCommunity,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I’m currently working on a task where I need to create a custom BIOC (Behavioral Indicator of Compromise) and add it to a restriction profile to block FTP command lines. Specifically, I want to prevent FTP-related commands from being executed by monitoring and restricting certain patterns.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also need help with incorporating the following regex expression into the scope of action for a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;remote IP&lt;BR /&gt;&lt;BR /&gt;it would be very appreciated if you have more details of how the BIOC must be created to block a process when it's associated with a restriction profile&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;An additional question is how BIOCs work when added as a Prevention Rule in a Restriction Profile.&lt;/P&gt;
&lt;P&gt;I can see that some rules can generate locks killing the process, and others only detect, does anyone know how this capability works?&lt;/P&gt;</description>
    <pubDate>Wed, 15 Jan 2025 22:28:25 GMT</pubDate>
    <dc:creator>J.Gammara</dc:creator>
    <dc:date>2025-01-15T22:28:25Z</dc:date>
    <item>
      <title>FTP Transfer Custom BIOC</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ftp-transfer-custom-bioc/m-p/1086033#M7751</link>
      <description>&lt;P&gt;Hello Palo Alto LiveCommunity,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I’m currently working on a task where I need to create a custom BIOC (Behavioral Indicator of Compromise) and add it to a restriction profile to block FTP command lines. Specifically, I want to prevent FTP-related commands from being executed by monitoring and restricting certain patterns.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also need help with incorporating the following regex expression into the scope of action for a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;remote IP&lt;BR /&gt;&lt;BR /&gt;it would be very appreciated if you have more details of how the BIOC must be created to block a process when it's associated with a restriction profile&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;An additional question is how BIOCs work when added as a Prevention Rule in a Restriction Profile.&lt;/P&gt;
&lt;P&gt;I can see that some rules can generate locks killing the process, and others only detect, does anyone know how this capability works?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 22:28:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ftp-transfer-custom-bioc/m-p/1086033#M7751</guid>
      <dc:creator>J.Gammara</dc:creator>
      <dc:date>2025-01-15T22:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: FTP Transfer Custom BIOC</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ftp-transfer-custom-bioc/m-p/1086305#M7753</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1561359921"&gt;@J.Gammara&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;With BIOC rules, you can configure custom prevention rules to terminate the causality chain of a malicious process according to the Action Mode defined in the associated Restrictions Security Profile and trigger Cortex XDR Agent behavioral prevention type alerts in addition to the BIOC rule detection alerts.&lt;/P&gt;
&lt;P&gt;For example, if you configure a custom prevention rule for a BIOC Process event, apply it to the Restrictions profile with an action mode set to Block, the Cortex XDR agent:&lt;/P&gt;
&lt;P&gt;Blocks a process at the endpoint level according to the defined rule properties.&lt;/P&gt;
&lt;P&gt;Triggers a behavioral prevention alert you can monitor and investigate in the Alerts table.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information on how to create a BIOC rule, please refer below doc.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Create-a-BIOC-rule" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Create-a-BIOC-rule&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will find information on how to make a customer prevention rule using BIOC under heading&amp;nbsp;"Configure a custom prevention rule".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please c&lt;SPAN&gt;lick&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;to acknowledge that the answer to your question has been provided.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2025 04:45:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ftp-transfer-custom-bioc/m-p/1086305#M7753</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2025-01-16T04:45:11Z</dc:date>
    </item>
  </channel>
</rss>

