Does Cortex XDR BIOC analytics alerts get blocked after setting Global Behavioral Threat Protection to block

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Does Cortex XDR BIOC analytics alerts get blocked after setting Global Behavioral Threat Protection to block

L2 Linker

Hello team,

 

Does Cortex XDR BIOC analytics alerts get blocked after setting Global Behavioral Threat Protection to block ? or how Cortex XDR decide to block/detect the behavioral threat alert?

 

Cortex XDR 

1 REPLY 1

L4 Transporter

Hello @tejaspatil12 

 

Thanks for reaching out on LiveCommunity!

Analytics BIOC alerts are for detect/alert purpose they do not provide block functionality. Analytics BIOCs are not produced in real time and therefore cannot block. Please take a look at the Analytics Concepts. for a better understanding of how analytics work.  Essentially it's looking at a lot of different factors after the event to determine the larger picture.

By looking into the activity that caused the alert you may be able to find similarities you can use to create a high fidelity BIOC and then you can configure BIOC rules as custom prevention rules and incorporate them with your Restrictions profiles.

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Working-wit...

 

Please click Accept as Solution to acknowledge that the answer to your question has been provided.

  • 754 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!