Cortex XDR Identify Certain Execution

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cortex XDR Identify Certain Execution

I want cortex to generate an incident if a specific file(mp4, jpg) is executed. Is there any possibility to do this? How is that?


L4 Transporter

Hi @Tharaka-Wijesinghe , thanks for reaching the Live Community.


Yes, you can create a custom BIOC rule in Detection Rules -> BIOC -> + Add BIOC

In this example I'm monitoring zip files, but you can create the file extensios you need with the "*" wildcard.



Please let me know if this works for you.



Hi Jmazzeo


I created the rule and when I tested it, it showed me some incidents. Now I can't find the rule which I created. Can you just tell me from where I can see that Rule which I created and the incidents triggered against it??


Hi @Tharaka-Wijesinghe 


You can see and edit the created rule in the BIOC section, under Detection Rules -> BIOC.

The rule will have the name that you configured in the creation step., anyway you can use any filter to help you find it.


  • 3 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!