<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Verify default policy and custom on Cortex XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/verify-default-policy-and-custom-on-cortex-xdr/m-p/1235239#M8615</link>
    <description>&lt;P&gt;Dear Support,&lt;BR /&gt;&lt;BR /&gt;I would like to open case for verify and confirm on these tasks below:&lt;/P&gt;
&lt;P&gt;+ Currently we use this default rule on Cortex Prevention Policy Rules for customer that just enable it as protection mode but customer concern it’s not best practice recommendation and requested us to review all those settings again.&lt;/P&gt;
&lt;P&gt;+ IOC Rules – Ensure indicators of compromise are correctly configured, triggered and&amp;nbsp;IOC rule can be integrate with third party or not?&lt;BR /&gt;+ BIOC – Validate behavioral indicators of compromise for accuracy and relevance.&lt;BR /&gt;+ Host Firewall – Check host-based firewall configurations and policies. (we got this point)&lt;BR /&gt;+ Dashboard Customization – Review and confirm that dashboards are tailored to operational needs.&lt;/P&gt;
&lt;P&gt;So I need to open case and arrange session to confirm with customer together&lt;/P&gt;</description>
    <pubDate>Sat, 02 Aug 2025 06:14:54 GMT</pubDate>
    <dc:creator>CChan50</dc:creator>
    <dc:date>2025-08-02T06:14:54Z</dc:date>
    <item>
      <title>Verify default policy and custom on Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/verify-default-policy-and-custom-on-cortex-xdr/m-p/1235239#M8615</link>
      <description>&lt;P&gt;Dear Support,&lt;BR /&gt;&lt;BR /&gt;I would like to open case for verify and confirm on these tasks below:&lt;/P&gt;
&lt;P&gt;+ Currently we use this default rule on Cortex Prevention Policy Rules for customer that just enable it as protection mode but customer concern it’s not best practice recommendation and requested us to review all those settings again.&lt;/P&gt;
&lt;P&gt;+ IOC Rules – Ensure indicators of compromise are correctly configured, triggered and&amp;nbsp;IOC rule can be integrate with third party or not?&lt;BR /&gt;+ BIOC – Validate behavioral indicators of compromise for accuracy and relevance.&lt;BR /&gt;+ Host Firewall – Check host-based firewall configurations and policies. (we got this point)&lt;BR /&gt;+ Dashboard Customization – Review and confirm that dashboards are tailored to operational needs.&lt;/P&gt;
&lt;P&gt;So I need to open case and arrange session to confirm with customer together&lt;/P&gt;</description>
      <pubDate>Sat, 02 Aug 2025 06:14:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/verify-default-policy-and-custom-on-cortex-xdr/m-p/1235239#M8615</guid>
      <dc:creator>CChan50</dc:creator>
      <dc:date>2025-08-02T06:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: Verify default policy and custom on Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/verify-default-policy-and-custom-on-cortex-xdr/m-p/1235250#M8616</link>
      <description>&lt;P&gt;The default ruleset is a starting point, but it's often not the most optimized for their specific environment. You should review the following with your customer:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Customization: The default rules are broad. The goal is to create more granular policies for specific groups of endpoints. For example, a development server might have different security needs than an employee's laptop.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&amp;nbsp;You can work with your customer to create custom profiles that apply to specific endpoint groups, ensuring a balance between strong security and business functionality.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Continuous Improvement: Prevention policies are not a one-time setup. They should be reviewed and fine-tuned regularly based on new threats and changes in the customer's environment.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;IOC and BIOC Rules&lt;/H3&gt;
&lt;P&gt;This is a critical area for both detection and integration. You should cover these points with your customer:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;IOCs (Indicators of Compromise): You can confirm that IOCs are correctly configured and triggered by showing them how to view and manage IOC rules within the Cortex XDR console. You can also show how IOCs are automatically created from threat intelligence feeds. Cortex XDR can integrate with third-party threat intelligence platforms like Cortex XSOAR to ingest IOCs, which allows for a more comprehensive defense.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="citation-7"&gt;BIOCs (Behavioral Indicators of Compromise):&lt;/SPAN&gt;&lt;SPAN class="citation-7 citation-end-7"&gt; These are custom detection rules that use the Cortex Query Language (XQL).&lt;/SPAN&gt; You should validate with the customer that their BIOCs are accurate and relevant by reviewing the queries. &lt;SPAN class="citation-6 citation-end-6"&gt;BIOCs are powerful because they detect behaviors rather than just static indicators, which is crucial for catching sophisticated attacks.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Host Firewall and Dashboard Customization&lt;/H3&gt;
&lt;P&gt;&lt;SPAN class="citation-5"&gt;Host Firewall:&lt;/SPAN&gt;&lt;SPAN class="citation-5"&gt; Cortex XDR's host firewall allows you to &lt;/SPAN&gt;&lt;SPAN class="citation-5"&gt;control inbound and outbound communications&lt;/SPAN&gt;&lt;SPAN class="citation-5 citation-end-5"&gt; on Windows and macOS endpoints.&lt;/SPAN&gt; You can demonstrate how to create and manage host firewall policies and apply them to different endpoint groups. This centralizes control and ensures consistent security across all managed devices.&lt;/P&gt;
&lt;P&gt;Dashboard: Customization: You can show the customer how to tailor dashboards to their operational needs. &lt;SPAN class="citation-4 citation-end-4"&gt;Cortex XDR allows users to create custom dashboards and widgets to display the most relevant information for their security team.&lt;/SPAN&gt; This helps them prioritize and investigate incidents more efficiently by providing a clear, focused view of their environment.&lt;/P&gt;
&lt;H3&gt;Next Steps&lt;/H3&gt;
&lt;P&gt;I recommend you create a case with the customer and schedule a follow-up session. In this session, you can walk through the Cortex XDR console together and address each of their concerns point by point. This hands-on approach will build confidence and ensure the customer's environment is configured for maximum protection.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Aug 2025 17:10:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/verify-default-policy-and-custom-on-cortex-xdr/m-p/1235250#M8616</guid>
      <dc:creator>Mudhireddy</dc:creator>
      <dc:date>2025-08-03T17:10:47Z</dc:date>
    </item>
  </channel>
</rss>

