- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-04-2023 03:34 AM
I want cortex to generate an incident if a specific file(mp4, jpg) is executed. Is there any possibility to do this? How is that?
10-04-2023 06:34 AM
Hi @Tharaka-Wijesinghe , thanks for reaching the Live Community.
Yes, you can create a custom BIOC rule in Detection Rules -> BIOC -> + Add BIOC
In this example I'm monitoring zip files, but you can create the file extensios you need with the "*" wildcard.
Please let me know if this works for you.
10-04-2023 09:18 PM
Hi Jmazzeo
I created the rule and when I tested it, it showed me some incidents. Now I can't find the rule which I created. Can you just tell me from where I can see that Rule which I created and the incidents triggered against it??
10-05-2023 05:05 AM
You can see and edit the created rule in the BIOC section, under Detection Rules -> BIOC.
The rule will have the name that you configured in the creation step., anyway you can use any filter to help you find it.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!