- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-27-2025 01:25 PM
I have dual homed systems with one of the IP addresses being publicly routable due to a cellular connection. My goal is to use Cortex to block traffic destined to those public IPs. An XQL query has been constructed to match traffic I would like to block, and I have created a BIOC that meets the intent as well, however I'm not seeing that BIOC as a custom prevention rule when I set up the restriction profile.
Does anyone have a suggestion on how to best handle this?
Thanks!
09-03-2025 06:43 AM
Hi @mike_dunlap
Cortex XDR is not intended to be used as a Fw to block traffic.
Im not sure what you are trying to do. I can tell you that once you have created a BIOC rule, depending on the type of BIOC you can add it to a restriction profile
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.
KR,
Luis
12-22-2025 11:36 AM
Hello @mike_dunlap
The Behavioral Indicator of Compromise (BIOC) you created is likely missing from the Restriction Profile because it contains fields or syntax that are not supported for agent-side prevention. Cortex XDR enforces strict eligibility criteria for BIOC rules to be used as Custom Prevention Rules (which run locally on the agent as Behavioral Threat Protection - BTP).
Best Approach for Blocking Traffic to Public IPs
While BIOCs can detect network connections, they are designed to terminate the process initiating the connection rather than performing network-layer filtering.
To block traffic destined for specific IPs on dual-homed systems, the Host Firewall module is the recommended solution.
1. Using the Host Firewall (Recommended):
* Navigate to Endpoints → Policy Management → Extensions → Host Firewall.
* Create a rule to block Outbound traffic where the Remote Address matches the public IPs you wish to restrict.
* This module leverages the Windows Filtering Platform (WFP) to explicitly drop packets at the network layer
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thanks & Regards,
S. Subashkar Sekar
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

