<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR: Bitlocker Monitoring in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-bitlocker-monitoring/m-p/418624#M857</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are looking at using XDR to monitor Bitlocker status on Windows machines. On the 'Disk Encryption Visibility' page, we can see the Encryption status, but there is no way to filter on 'Unencrypted' drives.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Does anyone know of an XQL Query to show only the drives unencrypted?&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Does anyone know of an XQL Query to tie to a BIOC and alert if a drive becomes unencrypted?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PBurns_0-1626116899345.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34986i083015852A857A27/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PBurns_0-1626116899345.png" alt="PBurns_0-1626116899345.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks for taking a look!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Peter&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 12 Jul 2021 20:47:41 GMT</pubDate>
    <dc:creator>PBurns</dc:creator>
    <dc:date>2021-07-12T20:47:41Z</dc:date>
    <item>
      <title>Cortex XDR: Bitlocker Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-bitlocker-monitoring/m-p/418624#M857</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are looking at using XDR to monitor Bitlocker status on Windows machines. On the 'Disk Encryption Visibility' page, we can see the Encryption status, but there is no way to filter on 'Unencrypted' drives.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Does anyone know of an XQL Query to show only the drives unencrypted?&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Does anyone know of an XQL Query to tie to a BIOC and alert if a drive becomes unencrypted?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PBurns_0-1626116899345.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34986i083015852A857A27/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PBurns_0-1626116899345.png" alt="PBurns_0-1626116899345.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks for taking a look!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Peter&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 20:47:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-bitlocker-monitoring/m-p/418624#M857</guid>
      <dc:creator>PBurns</dc:creator>
      <dc:date>2021-07-12T20:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR: Bitlocker Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-bitlocker-monitoring/m-p/419010#M858</link>
      <description>&lt;P&gt;It looks like we have ENCRYPTION STATUS in the Endpoints data set, but not VOLUME STATUS. At this point, we are not enforcing encryption by the policy. See below for a sample query provided by Palo Support:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;config case_sensitive = false |&lt;BR /&gt;dataset = endpoints&lt;BR /&gt;| filter encryption_status = NOT_CONFIGURED or encryption_status = NOT_COMPLIANT |&lt;BR /&gt;fields endpoint_name&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 16:45:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-bitlocker-monitoring/m-p/419010#M858</guid>
      <dc:creator>PBurns</dc:creator>
      <dc:date>2021-07-13T16:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR: Bitlocker Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-bitlocker-monitoring/m-p/419266#M859</link>
      <description>&lt;P&gt;Hello PBurns,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for the XQL query about status. for the BIOC question, you may write BIOC to checking specific registry path. Below is just one sample not tested but might help you to write a query for proper path.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FVE\OSEncryptionType&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;0 =&amp;nbsp;Allow user to choose (default)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1 =&amp;nbsp;Full encryption&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2 =&amp;nbsp;Used Space Only encryption&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="etugriceri_0-1626255597358.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35026i3B5C97BA69262BF1/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="etugriceri_0-1626255597358.png" alt="etugriceri_0-1626255597358.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or&amp;nbsp;&lt;/P&gt;&lt;P&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BitLocker&lt;/P&gt;&lt;P&gt;Value: PreventDeviceEncryption equal to True (1).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 09:49:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-bitlocker-monitoring/m-p/419266#M859</guid>
      <dc:creator>etugriceri</dc:creator>
      <dc:date>2021-07-14T09:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR: Bitlocker Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-bitlocker-monitoring/m-p/557731#M5142</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you made any progress?&lt;/P&gt;
&lt;P&gt;I would like to set up an alert for disks with unencrypted drives.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 14:41:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-bitlocker-monitoring/m-p/557731#M5142</guid>
      <dc:creator>Melvin_Machado</dc:creator>
      <dc:date>2023-09-13T14:41:50Z</dc:date>
    </item>
  </channel>
</rss>

