Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Blocking Domain/URL

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Blocking Domain/URL

Hi Team,

 

I know we can block IP addresses with new feature called host firewall,.Since the ip is dynamic , its not a good option for me. Is it possible to block url or domain in cortex xdr?

 

1 accepted solution

Accepted Solutions

L4 Transporter

Hi @Marsooq-Akkaradathil -


The current version of the product can only block an IP Address.  You can, create an IOC that will alert on this.  If you use XSOAR, you could also action on the IOC. 

 

dfalcon_0-1589860006792.png

 


David Falcon 
Senior Solutions Architect, Cortex
Palo Alto Networks® 

View solution in original post

2 REPLIES 2

L4 Transporter

Hi @Marsooq-Akkaradathil -


The current version of the product can only block an IP Address.  You can, create an IOC that will alert on this.  If you use XSOAR, you could also action on the IOC. 

 

dfalcon_0-1589860006792.png

 


David Falcon 
Senior Solutions Architect, Cortex
Palo Alto Networks® 

L3 Networker

Great thank you! Hope they add the new feature to block also domains if not URL with the host firewall. Till then if the customer also has Palo Alto firewalls maybe this is an option for the Cortex XDR to generate EDL lists that the Palo Alto firewall (Palo Alto Firewall and Cortex XDR integration) can consume:

 

https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/...

 

Also it is good to enable the firewalls access to the Cortex XDR and for the firewall to send its logs to the Cortex Data Lake so the Cortex XDR can see the network taffic:

 

https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/get-started-with-cortex...

 

https://www.paloaltonetworks.com/blog/2020/03/cortex-busted-by-cortex-xdr/

  • 1 accepted solution
  • 9017 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!