<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [Cortex] How to Block Multiple C2 IP Addresses Using Cortex XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-how-to-block-multiple-c2-ip-addresses-using-cortex-xdr/m-p/1227611#M8268</link>
    <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/308232"&gt;@aspatil&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Thanks for the reply, I know user can block IP address via HostFirewall, how would you recommend setting up the BIOC Rule?&lt;/P&gt;
&lt;P&gt;As mentioned earlier, I have tried to create BIOC Rule but it cannot&amp;nbsp;&lt;SPAN&gt;added to the Restrictions Profile&lt;/SPAN&gt;, rule details are provided below:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SLin576639_0-1745893742760.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67336i7FFC201D90A56484/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SLin576639_0-1745893742760.png" alt="SLin576639_0-1745893742760.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SLin576639_1-1745893763360.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67337iC14EE0A48F1BEFA1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SLin576639_1-1745893763360.png" alt="SLin576639_1-1745893763360.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Apr 2025 02:30:23 GMT</pubDate>
    <dc:creator>S.Lin576639</dc:creator>
    <dc:date>2025-04-29T02:30:23Z</dc:date>
    <item>
      <title>[Cortex] How to Block Multiple C2 IP Addresses Using Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-how-to-block-multiple-c2-ip-addresses-using-cortex-xdr/m-p/1227530#M8260</link>
      <description>&lt;P class="" data-start="148" data-end="162"&gt;Dear Everyone,&lt;/P&gt;
&lt;P class="" data-start="164" data-end="391"&gt;My customer has a requirement: they would like the Cortex XDR Agent to detect and block multiple specified C2 IP addresses.&lt;BR data-start="287" data-end="290" /&gt;I would like to ask if anyone has encountered a similar case or has any relevant experience to share.&lt;/P&gt;
&lt;P class="" data-start="393" data-end="724"&gt;Currently, I am aware that this can be achieved by configuring Host Firewall Rules, which fulfills the requirement.&lt;BR data-start="508" data-end="511" /&gt;Additionally, I have tried using a BIOC Rule to detect and block the specified IP addresses. However, I found that even though detection works, it cannot be directly added to the Restrictions Profile for blocking.&lt;/P&gt;
&lt;P class="" data-start="726" data-end="810"&gt;Any suggestions or alternative approaches would be greatly appreciated.&lt;BR data-start="797" data-end="800" /&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 08:27:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-how-to-block-multiple-c2-ip-addresses-using-cortex-xdr/m-p/1227530#M8260</guid>
      <dc:creator>S.Lin576639</dc:creator>
      <dc:date>2025-04-28T08:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: [Cortex] How to Block Multiple C2 IP Addresses Using Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-how-to-block-multiple-c2-ip-addresses-using-cortex-xdr/m-p/1227535#M8262</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113770349"&gt;@S.Lin576639&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alternative approach here is to use EDL:&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-External-Dynamic-Lists" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-External-Dynamic-Lists&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking like and&amp;nbsp; on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 09:48:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-how-to-block-multiple-c2-ip-addresses-using-cortex-xdr/m-p/1227535#M8262</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2025-04-28T09:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: [Cortex] How to Block Multiple C2 IP Addresses Using Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-how-to-block-multiple-c2-ip-addresses-using-cortex-xdr/m-p/1227541#M8265</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/308232"&gt;@aspatil&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;EDL is provided by Cortex to the PA firewall as one of the ways to share blocked IPs or domains, right? Is it possible for the agent to block directly through EDL? Please let me know if I misunderstood anything. Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 10:19:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-how-to-block-multiple-c2-ip-addresses-using-cortex-xdr/m-p/1227541#M8265</guid>
      <dc:creator>S.Lin576639</dc:creator>
      <dc:date>2025-04-28T10:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: [Cortex] How to Block Multiple C2 IP Addresses Using Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-how-to-block-multiple-c2-ip-addresses-using-cortex-xdr/m-p/1227555#M8267</link>
      <description>&lt;UL data-start="872" data-end="1194"&gt;
&lt;LI class="" data-start="872" data-end="969"&gt;
&lt;P class="" data-start="874" data-end="969"&gt;&lt;STRONG data-start="874" data-end="882"&gt;EDLs&lt;/STRONG&gt;: &lt;SPAN class="relative -mx-px my-[-0.2rem] rounded px-px py-[0.2rem] transition-colors duration-100 ease-in-out"&gt;Used by Palo Alto Networks firewalls for network-level blocking&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="" data-start="971" data-end="1080"&gt;
&lt;P class="" data-start="973" data-end="1080"&gt;&lt;STRONG data-start="973" data-end="993"&gt;Cortex XDR Agent&lt;/STRONG&gt;: &lt;SPAN class="relative -mx-px my-[-0.2rem] rounded px-px py-[0.2rem] transition-colors duration-100 ease-in-out"&gt;Does not consume EDLs directly but can block IPs via host firewall rules and detect threats using BIOC rules.&lt;/SPAN&gt;​&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="" data-start="1082" data-end="1194"&gt;
&lt;P class="" data-start="1084" data-end="1194"&gt;&lt;STRONG data-start="1084" data-end="1107"&gt;Domain/URL Blocking&lt;/STRONG&gt;: &lt;SPAN class="relative -mx-px my-[-0.2rem] rounded px-px py-[0.2rem] transition-colors duration-100 ease-in-out"&gt;Requires integration with firewalls, as the agent doesn't support this natively.&lt;/SPAN&gt;​&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="" data-start="1196" data-end="1304"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 12:13:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-how-to-block-multiple-c2-ip-addresses-using-cortex-xdr/m-p/1227555#M8267</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2025-04-28T12:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: [Cortex] How to Block Multiple C2 IP Addresses Using Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-how-to-block-multiple-c2-ip-addresses-using-cortex-xdr/m-p/1227611#M8268</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/308232"&gt;@aspatil&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Thanks for the reply, I know user can block IP address via HostFirewall, how would you recommend setting up the BIOC Rule?&lt;/P&gt;
&lt;P&gt;As mentioned earlier, I have tried to create BIOC Rule but it cannot&amp;nbsp;&lt;SPAN&gt;added to the Restrictions Profile&lt;/SPAN&gt;, rule details are provided below:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SLin576639_0-1745893742760.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67336i7FFC201D90A56484/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SLin576639_0-1745893742760.png" alt="SLin576639_0-1745893742760.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SLin576639_1-1745893763360.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67337iC14EE0A48F1BEFA1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SLin576639_1-1745893763360.png" alt="SLin576639_1-1745893763360.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 02:30:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-how-to-block-multiple-c2-ip-addresses-using-cortex-xdr/m-p/1227611#M8268</guid>
      <dc:creator>S.Lin576639</dc:creator>
      <dc:date>2025-04-29T02:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: [Cortex] How to Block Multiple C2 IP Addresses Using Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-how-to-block-multiple-c2-ip-addresses-using-cortex-xdr/m-p/1227613#M8269</link>
      <description>&lt;P&gt;Using "Network" instead of "Network Connection" when creating BIOC rules, then you should add&amp;nbsp; this to restriction profile respectively.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 03:26:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-how-to-block-multiple-c2-ip-addresses-using-cortex-xdr/m-p/1227613#M8269</guid>
      <dc:creator>SeanDeHarris</dc:creator>
      <dc:date>2025-04-29T03:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: [Cortex] How to Block Multiple C2 IP Addresses Using Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-how-to-block-multiple-c2-ip-addresses-using-cortex-xdr/m-p/1227960#M8282</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184443"&gt;@SeanDeHarris&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Thanks for your reply, I used “Network” to recreate the BIOC rules, but it still can't add the &lt;SPAN&gt;restriction&lt;/SPAN&gt;&amp;nbsp;profile.&lt;/P&gt;
&lt;P&gt;Bioc rule detail：&lt;/P&gt;
&lt;P&gt;Network [ action type = all AND remote ip = 14.139.185.60 ]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In addition, User connects to a specific C2 IP by pinging, but I observed it through “Network” and “Network Connection” respectively, and found that the connection record is only found in “Network Connection”.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please refer to the attached photos for the above screenshots.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 May 2025 08:52:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-how-to-block-multiple-c2-ip-addresses-using-cortex-xdr/m-p/1227960#M8282</guid>
      <dc:creator>S.Lin576639</dc:creator>
      <dc:date>2025-05-02T08:52:10Z</dc:date>
    </item>
  </channel>
</rss>

