<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IOC Function in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ioc-function/m-p/428105#M979</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191261"&gt;@Muhammad-Rusli&lt;/a&gt;,&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xdr-indicators.html" target="_self"&gt;XDR Indicator rules&lt;/A&gt; (E.g. BIOC and IOC) are detection rules; therefore, they do not include prevention functionality. These rules will create a detection alert once the criteria has been met.&amp;nbsp;&lt;SPAN&gt;You could also create a BIOC rule based on specific behavior and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xdr-indicators/working-with-biocs/create-a-bioc-rule.html#:~:text=your%20BIOC%20rule.-,Configure%20a%20Custom%20Prevention%20Rule,-Custom%20prevention%20rules" target="_self" rel="nofollow noopener noreferrer"&gt;add that BIOC to a Restriction profile&lt;/A&gt;. The situation that you described sounds like a use-case to &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/response-actions/manage-external-dynamic-lists" target="_self"&gt;manage external dynamic lists&lt;/A&gt;.&amp;nbsp; Please note, there are some requirements that need to be met in order to leverage this feature:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;To maintain an EDL in Cortex XDR, you must meet the following requirements:&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;Cortex XDR Pro per TB or Cortex Pro per Endpoint license&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;An&lt;SPAN&gt; App Administrator,&amp;nbsp;Privileged Investigator, or&amp;nbsp;Privileged Security Admin&amp;nbsp;&lt;/SPAN&gt;role which include EDL permissions&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;Palo Alto Networks firewall running PAN-OS 9.0 or a later release&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;Access to your Palo Alto Networks firewall configuration&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;</description>
    <pubDate>Fri, 20 Aug 2021 14:41:13 GMT</pubDate>
    <dc:creator>WSeldenIII</dc:creator>
    <dc:date>2021-08-20T14:41:13Z</dc:date>
    <item>
      <title>IOC Function</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ioc-function/m-p/427954#M974</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Until now, I cant understood a function from IOC in Cortex XDR.&lt;/P&gt;&lt;P&gt;Could please share to me what's a main function IOC XDR?&lt;/P&gt;&lt;P&gt;Because I have tried to create new rules, for block link m.facebook , like a picture.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MuhammadRusli_0-1629424930850.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35802iAB0055BEF6570153/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MuhammadRusli_0-1629424930850.png" alt="MuhammadRusli_0-1629424930850.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, after that I have tried to access again, and the result I keep can access the URL.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 02:03:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ioc-function/m-p/427954#M974</guid>
      <dc:creator>Muhammad-Rusli</dc:creator>
      <dc:date>2021-08-20T02:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: IOC Function</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ioc-function/m-p/428105#M979</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191261"&gt;@Muhammad-Rusli&lt;/a&gt;,&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xdr-indicators.html" target="_self"&gt;XDR Indicator rules&lt;/A&gt; (E.g. BIOC and IOC) are detection rules; therefore, they do not include prevention functionality. These rules will create a detection alert once the criteria has been met.&amp;nbsp;&lt;SPAN&gt;You could also create a BIOC rule based on specific behavior and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xdr-indicators/working-with-biocs/create-a-bioc-rule.html#:~:text=your%20BIOC%20rule.-,Configure%20a%20Custom%20Prevention%20Rule,-Custom%20prevention%20rules" target="_self" rel="nofollow noopener noreferrer"&gt;add that BIOC to a Restriction profile&lt;/A&gt;. The situation that you described sounds like a use-case to &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/response-actions/manage-external-dynamic-lists" target="_self"&gt;manage external dynamic lists&lt;/A&gt;.&amp;nbsp; Please note, there are some requirements that need to be met in order to leverage this feature:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;To maintain an EDL in Cortex XDR, you must meet the following requirements:&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;Cortex XDR Pro per TB or Cortex Pro per Endpoint license&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;An&lt;SPAN&gt; App Administrator,&amp;nbsp;Privileged Investigator, or&amp;nbsp;Privileged Security Admin&amp;nbsp;&lt;/SPAN&gt;role which include EDL permissions&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;Palo Alto Networks firewall running PAN-OS 9.0 or a later release&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;Access to your Palo Alto Networks firewall configuration&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 20 Aug 2021 14:41:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/ioc-function/m-p/428105#M979</guid>
      <dc:creator>WSeldenIII</dc:creator>
      <dc:date>2021-08-20T14:41:13Z</dc:date>
    </item>
  </channel>
</rss>

