- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-17-2025 10:51 AM - edited 03-17-2025 11:03 AM
I have created and conducted some forensic cases on Cortex XDR, but one thing that has always intrigued me is the "Alert" tab in the Forensic Investigation section. Does this tab contain alerts generated by the automatic artifact analysis feature based on behavior rules? And how can I utilize this feature, as I have never seen any alerts appear in this tab?
03-18-2025 12:36 AM
Hello @D.Tran166255 ,
The purpose is to view any alerts triggered during data ingested as part of the investigation.
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.
03-18-2025 12:50 AM
Thanks you for your time in this topic,
I performed triage and threat hunting across numerous machines, resulting in thousands of ingested files. While I'm certain there are suspicious activities present, no alerts were triggered. Are the rules used to trigger alerts for these files based on BIOC? Is it possible for me to write custom rules to trigger alerts for ingested files? Are there any prerequisites I need to fulfill before enabling this functionality?
03-20-2025 01:04 AM
After a day of research, I understand that data is ingested into Cortex XDR using the Cortex XDR Forensics Add-on with forensics datasets. If I want to query this data, I need to call the datasets I highlighted in the image below. However, in BIOC, only the xdr_data and cloud_audit_log datasets can be used. Therefore, it's impossible to write BIOC rules for data from the Forensics Add-on and only IOCs can be used to create alerts for them. Is my understanding correct?
Thank you for taking the time for me.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!