Is it possible to block IOC from Cortex XDR?

cancel
Showing results for 
Search instead for 
Did you mean: 

Is it possible to block IOC from Cortex XDR?

L2 Linker

I'm trying to block domain across in our environment. I don't want to use url filtering on PA FW, but I want to use XDR IOC to block it. is possible to do it? 

1 ACCEPTED SOLUTION

Accepted Solutions

L3 Networker

Hi Hpatel11,

 

Unfortunately, no, it is not possible to block IOCs with Cortex XDR directly, the IOCs exist only on the XDR server and are not sent to the agents.  If you are an XDR Pro per Endpoint or Pro per TB customer, you can set up External Dynamic Lists and have your NGFW subscribe to those lists to automatically update your firewall policy directly from XDR.  

View solution in original post

14 REPLIES 14

L3 Networker

Hi Hpatel11,

 

Unfortunately, no, it is not possible to block IOCs with Cortex XDR directly, the IOCs exist only on the XDR server and are not sent to the agents.  If you are an XDR Pro per Endpoint or Pro per TB customer, you can set up External Dynamic Lists and have your NGFW subscribe to those lists to automatically update your firewall policy directly from XDR.  

L2 Linker

I figured. Thanks! 

L4 Transporter

Hi @hpatel11 

if IOCs are hashes you can block them adding them to the block list

Then as Afurze mentioned you can add other IOCs or internet web-sites to the EDLs so you can block them on your FWs

Other indicators like malicious email senders can be added (by your own procedures) to email server black lists... 

Think of other tools you might have at your organization in order to appropriately block all kinds of IOCs

 

I hope this helps, 
Luis 

L3 Networker

I did this in my poc(long time ago), I blocked like www.heise.de through BIOC with restriction rule. 

When I surfed on this webpage the whole browser got closed. 

If you want I can repeat it in my cortex xdr pro per endpoint Environment. 

 

I checked on BIOC but don't see anything for Domain. I see that we can do by IP.

Have you tried to take a network query to view which field the domain is called? 

Got it it's called action_external_hostname Let me try to use this. 

L2 Linker

hpatel11_0-1660330535523.png

I was able to create BIOC but can't associate BIOC with prevention policy. It's not syntax issue because I was able to trigger alert on it. 

I think you need to do this from BIOC perspective. Not from the alert/incident perspective. 

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!