- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-01-2023 05:15 AM
We have 3 use cases for which we want to set up 3 rules in XDR, we would like to get your help to identify the best avenue to address them :
For each use case, please advise what feature to use (e.g.: BIOC, blocklist, correlation rule) and if a change in the profiles is required, as per your guides and best practices.
Cortex XDR @LiveCommunityMemberOD @JayGolf
12-05-2023 09:02 AM
Sorry this is the correct link Custom Prevention Rules| Palo Alto Networks
12-05-2023 08:18 AM - edited 12-05-2023 09:02 AM
Hi Mohitparashar,
Adding an IOC is a Detect Only indicator. We recommend that IOCs be added to the firewall policy to block as URL filtering is a Layer 7 mechanism and Cortex operates on Layer 3. If you are using a Palo Alto firewall you may leverage the EDL (Manage External Dynamic Lists ) to block the domain and IP.
For non-network events, you may create a custom BIOC using an XQL query to enable a custom prevention rule then add it to the Restrictions Profile applied to the endpoints as outlined in this video Custom Prevention Rules| Palo Alto Networks
The following describes the event_type values for which you can create a BIOC rule.
Once created, you can add the BIOC to restrictions profiles.
A few caveats...
Please note, XDR works on process instances termination and not network termination. For example, any network connection made using browsers for the URL (using a BIOC) will kill the browser itself and not just the network connection. As a result, all other browser tabs will also shut down. Therefore, adding a BIOC for domains/IPs is not a recommended action. It is recommended to set up a firewall configuration for URL filtering.
Reference
Threat Hunting with XDR | Palo Alto Networks
If you found this answer helpful, please select Accept as Solution.
Thank you
12-05-2023 08:58 AM
Hello @jtalton
My access to the video resource is denied.
https://live.paloaltonetworks.com/t5/shaolin-beta-articles/video-tutorial-custom-prevention-rules/ta...
Could you please help me with how to access and why it is getting denied?
Regards,
Mohit
12-05-2023 09:02 AM
Sorry this is the correct link Custom Prevention Rules| Palo Alto Networks
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!