cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who Me Too'd this topic

Yara Rules and Cortex XDR

L3 Networker

I have seen alerts screenshot on internet where an alert triggered after matching a Yara rules.

 

https://attackevals.mitre-engenuity.org/enterprise/participants/paloaltonetworks?adversary=carbanak-...

KanwarSingh01_1-1648928772751.png

(Fourth Screenshot)

 

Does Cortex XDR uses Yara Rules? I mean the screenshot answers it but how? Do we need to upgrade on a specific version of XDR agent? Can we build our own custom yara rules?

 

https://www.paloaltonetworks.com/cortex/cortex-xdr

KanwarSingh01_0-1648928403368.png

 

Would love to understand how it works.

Kind Regards
KS
Who Me Too'd this topic