Automatic Artifact Analysis in Forensic Investigation

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Automatic Artifact Analysis in Forensic Investigation

L1 Bithead

I have created and conducted some forensic cases on Cortex XDR, but one thing that has always intrigued me is the "Alert" tab in the Forensic Investigation section. Does this tab contain alerts generated by the automatic artifact analysis feature based on behavior rules? And how can I utilize this feature, as I have never seen any alerts appear in this tab?

DTran166255_0-1742234620832.png

Cortex XDR

5 REPLIES 5

L5 Sessionator

Hello @D.Tran166255 ,

 

The purpose is to view any alerts triggered during data ingested as part of the investigation.

 

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Manage-an-investigati...

 

If you feel this has answered your query, please let us know by clicking like and  on "mark this as a Solution". Thank you.

Ashutosh Patil

Thanks you for your time in this topic,

 

I performed triage and threat hunting across numerous machines, resulting in thousands of ingested files. While I'm certain there are suspicious activities present, no alerts were triggered. Are the rules used to trigger alerts for these files based on BIOC? Is it possible for me to write custom rules to trigger alerts for ingested files? Are there any prerequisites I need to fulfill before enabling this functionality?

DTran166255_0-1742284230456.png

 

 

 

L5 Sessionator

Yes there should be detection rules in place. Eg. IOC

Ashutosh Patil

After a day of research, I understand that data is ingested into Cortex XDR using the Cortex XDR Forensics Add-on with forensics datasets. If I want to query this data, I need to call the datasets I highlighted in the image below. However, in BIOC, only the xdr_data and cloud_audit_log datasets can be used. Therefore, it's impossible to write BIOC rules for data from the Forensics Add-on and only IOCs can be used to create alerts for them. Is my understanding correct?

Thank you for taking the time for me.

DTran166255_0-1742457848327.png

DTran166255_1-1742457875387.png

 

L5 Sessionator

Yes

Ashutosh Patil
  • 236 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!