Changing Analytics and BIOC Analytics Rules Severity and Configuring the Agent to Block

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Changing Analytics and BIOC Analytics Rules Severity and Configuring the Agent to Block

L3 Networker

Hello all,

I have identified that the Analytics and BIOC Analytics is identifying real threats yet no action has been initiated due to the log source. Is it possible to increase the severity of these rules to Medium and higher ? 

Secondy, is it possible to set the policy to block when identifying these specific rules on the XDR Tenant?

From what I understand of these rules is that due to the fact that they are built-in rules that are provided by PAN they cannot be altered or their conditions cannot be viewed. What can I do in order to allow the agent to actively target these threats?

Cortex XDR 

PCSAE
1 REPLY 1

L2 Linker

Is it possible to increase the severity of these rules to Medium and higher? Yes, you can manually change the incident severity by clicking on the three dots on the top right corner and select change severity.

Note: You cant change the actual rule severity that initially triggered the alert.

 

Is it possible to set the policy to block when identifying these specific rules on the XDR Tenant? No since these are analytics rules, but what you can do is investigate this analytics/bioc analytics alerts and create your custom BIOC rule based on your investigation/criteria then you can assign that custom bioc rule as prevention rule which you need to apply to restriction profile.

 

From what I understand of these rules is that due to the fact that they are built-in rules that are provided by PAN they cannot be altered or their conditions cannot be viewed. Correct

 

What can I do in order to allow the agent to actively target these threats? What you can do is investigate this analytics/bioc analytics alerts and create your custom BIOC rule based on your investigation/criteria then you can assign that custom bioc rule as prevention rule which you need to apply to restriction profile.

 

Reference: Configure Custom Prevention Rule:

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Create-a-BI...

https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/custom-prevention-rules/ta-p/347271

 

  • 1427 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!