- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
09-26-2024 08:30 AM
Guys,
I need your help, I need to upload 500 IOCs to the block list.
Is there any option to upload IOCs in bulk or I have upload one by one?
Cortex XDR
09-26-2024 08:33 AM
Hi @tlmarques, thanks for reaching us using the Live Community.
When you create the IOC in Detection Rules -> IOC, you click on Add IOC and you have the option to upload many entries using a file, and you have a sample file to create it with the correct format.
If this post answers your question, please mark it as the solution.
09-27-2024 09:02 AM
Hi @jmazzeo
but when i uploaded on IOCs , the IOC is not blocked, but only appear alerts on XDR correct??
09-27-2024 11:09 AM
I tested inserting IOCs marked as critical and with bad reputation. Cortex XDR automatically created multiple incidents/alerts, but the action taken was "detect" rather than "prevent," which is what I need.
Do you have any other suggestions on how to achieve this?
09-27-2024 11:22 AM
The IOC list is only to for detection. If you need to block the hashes execution you need to add them to a Block List under Incident Response - Response - Action Center -> Block List.
I highly recommend you the Alert Tuning webinar that was published in last April this year: https://live.paloaltonetworks.com/t5/cortex-xdr-webinars/cortex-xdr-customer-success-webinar-series-...
If this post answers your question, please mark it as the solution.
09-27-2024 11:44 AM
Yes, as I mentioned... I need to upload 500 IOCs to block...
Is there a bulk process?
I don’t think so...
09-27-2024 11:47 AM
Yes, you can add 100 at the same time from the console:
Or you can use the API: https://cortex-panw.stoplight.io/docs/cortex-xdr/1a1950467783e-block-list-files
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!