About Behavioral Threat Protection (BTP) rules
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

The Enhanced LIVEcommunity Experience is finally here! Learn all about it.

About Behavioral Threat Protection (BTP) rules

L1 Bithead

Hi Everyone:

Does anyone know where I can find Behavioral Threat Protection (BTP) rules?
For example, a behavioral threat is detected (rule: pp.epm_for_malware_behavior_j01)
or Behavior threat detected (rule: bioc.pp.ransom_prevention_final)

What do these two rules mean?


Thank you

 

Richard

1 ACCEPTED SOLUTION

Accepted Solutions

L4 Transporter

Hi @RichardChou,

 

The protection rule database is not publicly accessible at this time. To get information regarding the rules, why they were triggered, and recommendations on the next steps, please open a support case. They will likely need the Alert data to perform further analysis as well. That can be collected using the following instructions.

 

Steps to collect Alert Data from Cortex XDR Console:

1. Got to the Alerts table.
2. Right-click on your target alert
3. Select "Retrieve Additional Data," then "Retrieve alert data."
3. Navigate to Response > Action Center
5. Locate the alert data retrieval job that you created.
6. Right-click on your target job
7. Select "Additional Data."
8. Right-click on the resulting action
9. Select "Download Files."

--gjenkins

View solution in original post

2 REPLIES 2

L4 Transporter

Hi @RichardChou,

 

The protection rule database is not publicly accessible at this time. To get information regarding the rules, why they were triggered, and recommendations on the next steps, please open a support case. They will likely need the Alert data to perform further analysis as well. That can be collected using the following instructions.

 

Steps to collect Alert Data from Cortex XDR Console:

1. Got to the Alerts table.
2. Right-click on your target alert
3. Select "Retrieve Additional Data," then "Retrieve alert data."
3. Navigate to Response > Action Center
5. Locate the alert data retrieval job that you created.
6. Right-click on your target job
7. Select "Additional Data."
8. Right-click on the resulting action
9. Select "Download Files."

--gjenkins

View solution in original post

Hi  Gjenkins

 

Thanks for your reply.
I understand.

 

Richard

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!