<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Automatic Artifact Analysis in Forensic Investigation in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-artifact-analysis-in-forensic-investigation/m-p/1224075#M8077</link>
    <description>&lt;P&gt;Thanks you for your time in this topic,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I performed triage and threat hunting across numerous machines, resulting in thousands of ingested files. While I'm certain there are suspicious activities present, no alerts were triggered. Are the rules used to trigger alerts for these files based on BIOC? Is it possible for me to write custom rules to trigger alerts for ingested files? Are there any prerequisites I need to fulfill before enabling this functionality?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DTran166255_0-1742284230456.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66692i954BECB6829F7A63/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DTran166255_0-1742284230456.png" alt="DTran166255_0-1742284230456.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Mar 2025 07:50:12 GMT</pubDate>
    <dc:creator>Dzung_TranC</dc:creator>
    <dc:date>2025-03-18T07:50:12Z</dc:date>
    <item>
      <title>Automatic Artifact Analysis in Forensic Investigation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-artifact-analysis-in-forensic-investigation/m-p/1224031#M8074</link>
      <description>&lt;P&gt;I have created and conducted some forensic cases on Cortex XDR, but one thing that has always intrigued me is the "Alert" tab in the Forensic Investigation section. Does this tab contain alerts generated by the automatic artifact analysis feature based on behavior rules? And how can I utilize this feature, as I have never seen any alerts appear in this tab?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DTran166255_0-1742234620832.png" style="width: 569px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66682i4344A215EA84488A/image-dimensions/569x137?v=v2" width="569" height="137" role="button" title="DTran166255_0-1742234620832.png" alt="DTran166255_0-1742234620832.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 18:03:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-artifact-analysis-in-forensic-investigation/m-p/1224031#M8074</guid>
      <dc:creator>Dzung_TranC</dc:creator>
      <dc:date>2025-03-17T18:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Artifact Analysis in Forensic Investigation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-artifact-analysis-in-forensic-investigation/m-p/1224073#M8076</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/237648851"&gt;@Dzung_TranC&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The purpose is to view any alerts triggered during data ingested as part of the investigation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Manage-an-investigation" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Manage-an-investigation&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking like and&amp;nbsp; on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 07:36:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-artifact-analysis-in-forensic-investigation/m-p/1224073#M8076</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2025-03-18T07:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Artifact Analysis in Forensic Investigation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-artifact-analysis-in-forensic-investigation/m-p/1224075#M8077</link>
      <description>&lt;P&gt;Thanks you for your time in this topic,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I performed triage and threat hunting across numerous machines, resulting in thousands of ingested files. While I'm certain there are suspicious activities present, no alerts were triggered. Are the rules used to trigger alerts for these files based on BIOC? Is it possible for me to write custom rules to trigger alerts for ingested files? Are there any prerequisites I need to fulfill before enabling this functionality?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DTran166255_0-1742284230456.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66692i954BECB6829F7A63/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DTran166255_0-1742284230456.png" alt="DTran166255_0-1742284230456.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 07:50:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-artifact-analysis-in-forensic-investigation/m-p/1224075#M8077</guid>
      <dc:creator>Dzung_TranC</dc:creator>
      <dc:date>2025-03-18T07:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Artifact Analysis in Forensic Investigation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-artifact-analysis-in-forensic-investigation/m-p/1224084#M8081</link>
      <description>&lt;P&gt;Yes there should be detection rules in place. Eg. IOC&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 09:43:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-artifact-analysis-in-forensic-investigation/m-p/1224084#M8081</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2025-03-18T09:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Artifact Analysis in Forensic Investigation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-artifact-analysis-in-forensic-investigation/m-p/1224279#M8092</link>
      <description>&lt;P&gt;After a day of research, I understand that data is ingested into Cortex XDR using the Cortex XDR Forensics Add-on with forensics datasets. If I want to query this data, I need to call the datasets I highlighted in the image below. However, in BIOC, only the xdr_data and cloud_audit_log datasets can be used. Therefore, it's impossible to write BIOC rules for data from the Forensics Add-on and only IOCs can be used to create alerts for them. Is my understanding correct?&lt;/P&gt;
&lt;P&gt;Thank you for taking the time for me.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DTran166255_0-1742457848327.png" style="width: 919px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66728iF5A018AD1E4F3585/image-dimensions/919x449?v=v2" width="919" height="449" role="button" title="DTran166255_0-1742457848327.png" alt="DTran166255_0-1742457848327.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DTran166255_1-1742457875387.png" style="width: 906px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66729iB00B3B939ED59822/image-dimensions/906x107?v=v2" width="906" height="107" role="button" title="DTran166255_1-1742457875387.png" alt="DTran166255_1-1742457875387.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Mar 2025 08:04:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-artifact-analysis-in-forensic-investigation/m-p/1224279#M8092</guid>
      <dc:creator>Dzung_TranC</dc:creator>
      <dc:date>2025-03-20T08:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Artifact Analysis in Forensic Investigation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-artifact-analysis-in-forensic-investigation/m-p/1224292#M8093</link>
      <description>&lt;P&gt;Yes&lt;/P&gt;</description>
      <pubDate>Thu, 20 Mar 2025 12:08:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automatic-artifact-analysis-in-forensic-investigation/m-p/1224292#M8093</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2025-03-20T12:08:24Z</dc:date>
    </item>
  </channel>
</rss>

