- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-21-2023 02:40 PM
Hello dear community,
how could this keywords be integrated into cortex xdr pro?
https://mthcht.github.io/ThreatHunting-Keywords/
happy hunting!
BR
Rob
06-22-2023 12:51 PM
Hi @RFeyertag,
If you're wanting to set up detection rules these keywords there are a few ways you could do it.
You could use a custom script and interface with the API. Although a simpler method might just be to add these as appropriate BIOCs.
Let me know if you like either of these ideas.
06-22-2023 02:34 PM
Do you think this BIOC creation could be done by the experts from PA/Cortex XDR team?
BR
Rob
06-23-2023 05:19 AM
I believe some of these are currently protected out of the box with Cortex XDR and it's always possible more will be added in future content updates. Unless you've tested and confirmed I'd suggest adding them as BIOC's as each organization has different needs.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!