<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR - Blocked Hashes on newer systems do not show in Incidents in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocked-hashes-on-newer-systems-do-not-show-in/m-p/1227017#M8241</link>
    <description>&lt;P&gt;Thanks for explaining, i am testing out the custom BIOC.&lt;/P&gt;</description>
    <pubDate>Tue, 22 Apr 2025 06:05:15 GMT</pubDate>
    <dc:creator>Abdullah-Tariq</dc:creator>
    <dc:date>2025-04-22T06:05:15Z</dc:date>
    <item>
      <title>Cortex XDR - Blocked Hashes on newer systems do not show in Incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocked-hashes-on-newer-systems-do-not-show-in/m-p/1226955#M8238</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As the name suggests we have blocked certain hashes on Cortex XDR. However when a some new system runs the blocked hash file(s), they do get blocked a prompt is also shown on the system but there is no incident on Cortex Incident tab. Why is it so and how can i get it to show in incidents?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 07:37:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocked-hashes-on-newer-systems-do-not-show-in/m-p/1226955#M8238</guid>
      <dc:creator>Abdullah-Tariq</dc:creator>
      <dc:date>2025-04-21T07:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR - Blocked Hashes on newer systems do not show in Incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocked-hashes-on-newer-systems-do-not-show-in/m-p/1226971#M8239</link>
      <description>&lt;P class="" data-start="191" data-end="283"&gt;When you &lt;STRONG data-start="200" data-end="216"&gt;block a hash&lt;/STRONG&gt; in Cortex XDR (via &lt;STRONG data-start="236" data-end="259"&gt;Hash Control Policy&lt;/STRONG&gt; or manual blocklist),&lt;/P&gt;
&lt;UL data-start="284" data-end="501"&gt;
&lt;LI class="" data-start="284" data-end="353"&gt;
&lt;P class="" data-start="286" data-end="353"&gt;&lt;STRONG data-start="286" data-end="333"&gt;The agent blocks the file execution locally&lt;/STRONG&gt; on the endpoint&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="" data-start="354" data-end="429"&gt;
&lt;P class="" data-start="356" data-end="429"&gt;&lt;STRONG data-start="356" data-end="392"&gt;A prompt appears on the endpoint&lt;/STRONG&gt; (so the user knows it’s blocked)&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="" data-start="430" data-end="501"&gt;
&lt;P class="" data-start="432" data-end="501"&gt;&lt;STRONG data-start="432" data-end="439"&gt;BUT&lt;/STRONG&gt; — &lt;STRONG data-start="442" data-end="468"&gt;no incident is created&lt;/STRONG&gt; automatically in the console&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="" data-start="503" data-end="639"&gt;This is &lt;EM data-start="511" data-end="522"&gt;by design&lt;/EM&gt;. Cortex XDR treats &lt;STRONG data-start="542" data-end="559"&gt;hash blocking&lt;/STRONG&gt; as a &lt;STRONG data-start="565" data-end="594"&gt;policy enforcement action&lt;/STRONG&gt;, not necessarily as a &lt;STRONG data-start="617" data-end="638"&gt;security incident&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="" data-start="641" data-end="818"&gt;Unless the blocked file is &lt;STRONG data-start="668" data-end="749"&gt;associated with another detection (behavioral, exploit, malware module, etc.)&lt;/STRONG&gt;, it &lt;STRONG data-start="754" data-end="784"&gt;won't generate an incident&lt;/STRONG&gt; just because it’s a blocked hash.&lt;/P&gt;
&lt;P class="" data-start="641" data-end="818"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="641" data-end="818"&gt;And you can create a custom BIOC to generate a Alert like&lt;/P&gt;
&lt;P class="" data-start="641" data-end="818"&gt;&amp;nbsp;artifact.file_hash = &amp;lt;your_blocked_hash_value&amp;gt; &lt;BR /&gt;AND action.type = "blocked_execution"&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 12:03:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocked-hashes-on-newer-systems-do-not-show-in/m-p/1226971#M8239</guid>
      <dc:creator>Mudhireddy</dc:creator>
      <dc:date>2025-04-21T12:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR - Blocked Hashes on newer systems do not show in Incidents</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocked-hashes-on-newer-systems-do-not-show-in/m-p/1227017#M8241</link>
      <description>&lt;P&gt;Thanks for explaining, i am testing out the custom BIOC.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 06:05:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-blocked-hashes-on-newer-systems-do-not-show-in/m-p/1227017#M8241</guid>
      <dc:creator>Abdullah-Tariq</dc:creator>
      <dc:date>2025-04-22T06:05:15Z</dc:date>
    </item>
  </channel>
</rss>

