<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Monitoring Bluetooth in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/monitoring-bluetooth/m-p/1227236#M181</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are using Cortex XSIAM. Now we want to perform monitoring of Bluetooth in Microsoft Windows 10 and 11 computers. The reason we want to check whether our users are connecting their mobile phones, like iPhone and Androids, through their office laptop using Bluetooth&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XSIAM" id="Cortex_XSIAM"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Apr 2025 13:44:29 GMT</pubDate>
    <dc:creator>O.Faheem</dc:creator>
    <dc:date>2025-04-23T13:44:29Z</dc:date>
    <item>
      <title>Monitoring Bluetooth</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/monitoring-bluetooth/m-p/1227236#M181</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are using Cortex XSIAM. Now we want to perform monitoring of Bluetooth in Microsoft Windows 10 and 11 computers. The reason we want to check whether our users are connecting their mobile phones, like iPhone and Androids, through their office laptop using Bluetooth&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XSIAM" id="Cortex_XSIAM"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 13:44:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/monitoring-bluetooth/m-p/1227236#M181</guid>
      <dc:creator>O.Faheem</dc:creator>
      <dc:date>2025-04-23T13:44:29Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring Bluetooth</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/monitoring-bluetooth/m-p/1247946#M342</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1523226517"&gt;@O.Faheem&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, you can monitor and control Bluetooth connections on Windows 10 and 11 computers using Cortex XSIAM. This functionality is available starting with Cortex XDR Agent version 8.6.&lt;/P&gt;
&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4&gt;Requirements&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Agent Version:&lt;/STRONG&gt; Cortex XDR Agent 8.6 or later&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Operating System:&lt;/STRONG&gt; Windows 10 (Version 1809 and later) or Windows 11&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4&gt;Configuration Steps:&lt;/H4&gt;
&lt;P&gt;To monitor or block mobile phone connections via Bluetooth, configure a &lt;STRONG&gt;Device Control policy&lt;/STRONG&gt; within an Extensions profile:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Navigate to &lt;STRONG&gt;Endpoints → Policy Management → Prevention → Profiles&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Create or edit a &lt;STRONG&gt;Windows Device Configuration profile&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Locate the &lt;STRONG&gt;Bluetooth Devices&lt;/STRONG&gt; section.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Monitor Only:&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Set the policy to &lt;STRONG&gt;Allow&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Ensure &lt;STRONG&gt;Device Control logging&lt;/STRONG&gt; is enabled to capture connection events.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Block Mobile Phones&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Choose &lt;STRONG&gt;Custom settings&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Under &lt;STRONG&gt;Bluetooth Classic services&lt;/STRONG&gt;, select categories such as &lt;STRONG&gt;Phone&lt;/STRONG&gt; (including smartphone subcategories) to block.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Optionally, block specific &lt;STRONG&gt;Low Energy (LE) services&lt;/STRONG&gt; if needed.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4&gt;Monitoring and Detection:&lt;/H4&gt;
&lt;P&gt;Bluetooth connection events and data transfer activities are logged in XSIAM and can be queried using XQL.&lt;/P&gt;
&lt;P&gt;Example query:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;dataset = device_control_logs 
| filter device_type = "Bluetooth" 
| limit 100
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;HR /&gt;
&lt;H4&gt;Important Considerations and Limitations:&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Existing Connections:&lt;/STRONG&gt; Devices already paired when a block policy is applied may not be immediately disconnected. For the policy to take effect, manually unpair the device or restart the computer.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Phone Link Bypass:&lt;/STRONG&gt; Microsoft Phone Link may bypass Bluetooth-only file transfer blocks because it can use Wi-Fi or mobile data for transfers after the initial pairing.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Outbound Transfer Issues:&lt;/STRONG&gt; Some agent versions (8.6–8.8) may not consistently block outbound file transfers from laptop to phone; this is resolved in Agent 8.9.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Granularity:&lt;/STRONG&gt; Serial numbers for Bluetooth devices are not currently extracted; exceptions are typically based on &lt;STRONG&gt;Vendor ID&lt;/STRONG&gt; and &lt;STRONG&gt;Product ID&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Wed, 11 Feb 2026 14:39:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/monitoring-bluetooth/m-p/1247946#M342</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-02-11T14:39:31Z</dc:date>
    </item>
  </channel>
</rss>

