<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Create a IOC without incident in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/create-a-ioc-without-incident/m-p/1248570#M9148</link>
    <description>&lt;P data-start="133" data-end="148"&gt;Good morning,&lt;/P&gt;
&lt;P data-start="155" data-end="485"&gt;Today I would like to create a block for two malicious files that I found in our environment. I noticed that I can create an IOC to block paths, file names, IPs, etc. I have already created an IOC using a wildcard for the file name: &lt;STRONG data-start="388" data-end="407"&gt;PDFEditor_*.exe&lt;/STRONG&gt;, but I would also like to block the process without generating an incident.&lt;/P&gt;
&lt;P data-start="492" data-end="511"&gt;Is that possible?&lt;/P&gt;
&lt;P data-start="518" data-end="539"&gt;Thank you in advance.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Feb 2026 07:37:34 GMT</pubDate>
    <dc:creator>J.MorenoCiudad</dc:creator>
    <dc:date>2026-02-19T07:37:34Z</dc:date>
    <item>
      <title>Create a IOC without incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/create-a-ioc-without-incident/m-p/1248570#M9148</link>
      <description>&lt;P data-start="133" data-end="148"&gt;Good morning,&lt;/P&gt;
&lt;P data-start="155" data-end="485"&gt;Today I would like to create a block for two malicious files that I found in our environment. I noticed that I can create an IOC to block paths, file names, IPs, etc. I have already created an IOC using a wildcard for the file name: &lt;STRONG data-start="388" data-end="407"&gt;PDFEditor_*.exe&lt;/STRONG&gt;, but I would also like to block the process without generating an incident.&lt;/P&gt;
&lt;P data-start="492" data-end="511"&gt;Is that possible?&lt;/P&gt;
&lt;P data-start="518" data-end="539"&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2026 07:37:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/create-a-ioc-without-incident/m-p/1248570#M9148</guid>
      <dc:creator>J.MorenoCiudad</dc:creator>
      <dc:date>2026-02-19T07:37:34Z</dc:date>
    </item>
    <item>
      <title>Re: Create a IOC without incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/create-a-ioc-without-incident/m-p/1248584#M9151</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1588122947"&gt;@J.MorenoCiudad&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="flex flex-col text-sm pb-25"&gt;
&lt;ARTICLE class="text-token-text-primary w-full focus:outline-none [--shadow-height:45px] has-data-writing-block:pointer-events-none has-data-writing-block:-mt-(--shadow-height) has-data-writing-block:pt-(--shadow-height) [&amp;amp;:has([data-writing-block])&amp;gt;*]:pointer-events-auto [content-visibility:auto] supports-[content-visibility:auto]:[contain-intrinsic-size:auto_100lvh] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" tabindex="-1" data-turn-id="request-WEB:4c8782b3-3c9d-4157-b8cf-d0c7b78cfd7c-0" data-testid="conversation-turn-2" data-scroll-anchor="true" data-turn="assistant"&gt;
&lt;DIV class="text-base my-auto mx-auto pb-10 [--thread-content-margin:--spacing(4)] @w-sm/main:[--thread-content-margin:--spacing(6)] @w-lg/main:[--thread-content-margin:--spacing(16)] px-(--thread-content-margin)"&gt;
&lt;DIV class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn" tabindex="-1"&gt;
&lt;DIV class="flex max-w-full flex-col grow"&gt;
&lt;DIV class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal [.text-message+&amp;amp;]:mt-1" dir="auto" data-message-author-role="assistant" data-message-id="c2745efd-de2f-4267-b9b3-8b8f944ecfb8" data-message-model-slug="gpt-5-2"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden first:pt-[1px]"&gt;
&lt;DIV class="markdown prose dark:prose-invert w-full wrap-break-word light markdown-new-styling"&gt;
&lt;P data-start="0" data-end="222"&gt;Yes, it is possible to block these files without generating an incident, but this requires a combination of a &lt;STRONG data-start="110" data-end="133"&gt;Restriction Profile&lt;/STRONG&gt; for the blocking action and an &lt;STRONG data-start="165" data-end="189"&gt;Alert Exclusion rule&lt;/STRONG&gt; to suppress incident generation.&lt;/P&gt;
&lt;P data-start="0" data-end="222"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="224" data-end="373"&gt;Native Indicator of Compromise (IOC) rules are designed for detection and alerting only and do not inherently support prevention or blocking actions.&lt;/P&gt;
&lt;HR data-start="375" data-end="378" /&gt;
&lt;H4 data-start="380" data-end="456"&gt;To achieve a “silent block” for your malicious files, follow these steps:&lt;/H4&gt;
&lt;H5 data-start="458" data-end="514"&gt;1. Create a Restriction Profile to Block by Filename&lt;/H5&gt;
&lt;P data-start="516" data-end="683"&gt;While the global &lt;STRONG data-start="533" data-end="547"&gt;Block List&lt;/STRONG&gt; in the Action Center only supports SHA256 hashes, you can use a &lt;STRONG data-start="612" data-end="635"&gt;Restriction Profile&lt;/STRONG&gt; to block execution based on filename wildcards.&lt;/P&gt;
&lt;P data-start="685" data-end="697"&gt;Navigate to:&lt;/P&gt;
&lt;P data-start="699" data-end="756"&gt;&lt;STRONG data-start="699" data-end="756"&gt;Endpoints &amp;gt; Policy Management &amp;gt; Prevention &amp;gt; Profiles&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL data-start="758" data-end="980"&gt;
&lt;LI data-start="758" data-end="786"&gt;
&lt;P data-start="761" data-end="786"&gt;Click &lt;STRONG data-start="767" data-end="784"&gt;+ Add Profile&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="787" data-end="830"&gt;
&lt;P data-start="790" data-end="830"&gt;Select the relevant OS (e.g., Windows)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="831" data-end="879"&gt;
&lt;P data-start="834" data-end="879"&gt;Choose &lt;STRONG data-start="841" data-end="857"&gt;Restrictions&lt;/STRONG&gt; as the profile type&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="880" data-end="949"&gt;
&lt;P data-start="883" data-end="949"&gt;In the profile settings, locate the &lt;STRONG data-start="919" data-end="939"&gt;Executable files&lt;/STRONG&gt; section&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="950" data-end="980"&gt;
&lt;P data-start="953" data-end="980"&gt;Add your wildcard pattern&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-start="982" data-end="1064"&gt;To ensure the file is blocked regardless of its directory, use a leading wildcard:&lt;/P&gt;
&lt;DIV class="contain-inline-size rounded-2xl corner-superellipse/1.1 relative bg-token-sidebar-surface-primary"&gt;
&lt;DIV class="sticky top-[calc(var(--sticky-padding-top)+9*var(--spacing))]"&gt;
&lt;DIV class="absolute end-0 bottom-0 flex h-9 items-center pe-2"&gt;
&lt;DIV class="bg-token-bg-elevated-secondary text-token-text-secondary flex items-center gap-4 rounded-sm px-2 font-sans text-xs"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;&lt;CODE class="whitespace-pre!"&gt;&lt;SPAN&gt;&lt;SPAN class="hljs-emphasis"&gt;*PDFEditor_*&lt;/SPAN&gt;.exe
&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;OL start="6" data-start="1092" data-end="1194"&gt;
&lt;LI data-start="1092" data-end="1113"&gt;
&lt;P data-start="1095" data-end="1113"&gt;Save the profile&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1114" data-end="1194"&gt;
&lt;P data-start="1117" data-end="1194"&gt;Ensure it is assigned to a &lt;STRONG data-start="1144" data-end="1159"&gt;Policy Rule&lt;/STRONG&gt; applied to your target endpoints&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR data-start="1196" data-end="1199" /&gt;
&lt;H4 data-start="1201" data-end="1248"&gt;2. Suppress Incidents Using Alert Exclusion&lt;/H4&gt;
&lt;P data-start="1250" data-end="1427"&gt;By default, a block action will trigger a prevention alert and generate an incident. To prevent this, create an &lt;STRONG data-start="1362" data-end="1381"&gt;Alert Exclusion&lt;/STRONG&gt; rule to suppress the resulting notifications.&lt;/P&gt;
&lt;P data-start="1429" data-end="1441"&gt;Navigate to:&lt;/P&gt;
&lt;P data-start="1443" data-end="1498"&gt;&lt;STRONG data-start="1443" data-end="1498"&gt;Configuration &amp;gt; Incident &amp;amp; Alerts &amp;gt; Alert Exclusion&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL data-start="1500" data-end="1596"&gt;
&lt;LI data-start="1500" data-end="1535"&gt;
&lt;P data-start="1503" data-end="1535"&gt;Click &lt;STRONG data-start="1509" data-end="1533"&gt;+ Add Exclusion Rule&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1536" data-end="1596"&gt;
&lt;P data-start="1539" data-end="1596"&gt;Define the exclusion criteria to match the block events&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-start="1598" data-end="1616"&gt;You can filter by:&lt;/P&gt;
&lt;UL data-start="1618" data-end="1719"&gt;
&lt;LI data-start="1618" data-end="1658"&gt;
&lt;P data-start="1620" data-end="1658"&gt;&lt;STRONG data-start="1620" data-end="1630"&gt;Field:&lt;/STRONG&gt; Action Process Image Name&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1659" data-end="1685"&gt;
&lt;P data-start="1661" data-end="1685"&gt;&lt;STRONG data-start="1661" data-end="1674"&gt;Operator:&lt;/STRONG&gt; wildcard&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1686" data-end="1719"&gt;
&lt;P data-start="1688" data-end="1719"&gt;&lt;STRONG data-start="1688" data-end="1698"&gt;Value:&lt;/STRONG&gt; &lt;CODE data-start="1699" data-end="1717"&gt;*PDFEditor_*.exe&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="1721" data-end="1816"&gt;Alternatively, you can filter by the specific &lt;STRONG data-start="1767" data-end="1780"&gt;Rule Name&lt;/STRONG&gt; defined in the Restriction Profile.&lt;/P&gt;
&lt;OL start="3" data-start="1818" data-end="1836"&gt;
&lt;LI data-start="1818" data-end="1836"&gt;
&lt;P data-start="1821" data-end="1836"&gt;Save the rule&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-start="1838" data-end="1968"&gt;This will globally suppress alerts and incidents matching these criteria while allowing the agent to continue enforcing the block.&lt;/P&gt;
&lt;HR data-start="1970" data-end="1973" /&gt;
&lt;H4 data-start="1975" data-end="2002"&gt;Important Considerations:&lt;/H4&gt;
&lt;P data-start="2004" data-end="2176"&gt;&lt;STRONG data-start="2004" data-end="2024"&gt;IOC Limitations:&lt;/STRONG&gt;&lt;BR data-start="2024" data-end="2027" /&gt;Standard IOC rules are primarily used for threat hunting and post-execution visibility; they do not function as a pre-execution prevention mechanism.&lt;/P&gt;
&lt;P data-start="2004" data-end="2176"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="2178" data-end="2350"&gt;&lt;STRONG data-start="2178" data-end="2197"&gt;Bypassing Risk:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-start="2178" data-end="2350"&gt;&lt;BR data-start="2197" data-end="2200" /&gt;Blocking by filename or wildcard is less reliable than hash-based blocking, as an attacker can easily rename the executable to bypass the restriction.&lt;/P&gt;
&lt;P data-start="2178" data-end="2350"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="2352" data-end="2482" data-is-last-node="" data-is-only-node=""&gt;If the hashes are known, adding them to the global &lt;STRONG data-start="2403" data-end="2417"&gt;Block List&lt;/STRONG&gt; via the Action Center is the recommended security best practice.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/ARTICLE&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2026 13:19:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/create-a-ioc-without-incident/m-p/1248584#M9151</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-02-19T13:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: Create a IOC without incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/create-a-ioc-without-incident/m-p/1248634#M9159</link>
      <description>&lt;P data-start="98" data-end="106"&gt;Hello,&lt;/P&gt;
&lt;P data-start="113" data-end="301"&gt;Thank you for your answer. However, I have a doubt about it. What is the difference between creating the block using step 1 that you described and creating an IOC based on the file name?&lt;/P&gt;
&lt;P data-start="308" data-end="402"&gt;On the other hand, I have followed step 2 to suppress the incident using an alert exclusion.&lt;/P&gt;
&lt;P data-start="409" data-end="429"&gt;Thank you very much.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Feb 2026 06:47:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/create-a-ioc-without-incident/m-p/1248634#M9159</guid>
      <dc:creator>J.MorenoCiudad</dc:creator>
      <dc:date>2026-02-20T06:47:51Z</dc:date>
    </item>
  </channel>
</rss>

