Create an IOC rule - From the Cortex Cloud management console, you can upload or configure the indicator of compromise (IOC) rules criteria. - Administrator Guide - Cortex CLOUD

Cortex Cloud Runtime Security Documentation

Product
Cortex Cloud Application Security > Cortex CLOUD
License
Cloud Runtime Security
Creation date
2024-12-24
Last date published
2026-06-10
Category
Administrator Guide
Abstract

From the Cortex Cloud management console, you can upload or configure the indicator of compromise (IOC) rules criteria.

Create new indicator of compromise (IOC) rules and optionally define rule expiration for all IOC rules. You can create an IOC rule either by configuring a single one or by uploading a file that contains multiple IOCs.

Note

To ensure your IOC rules generate issues efficiently and do not overcrowd your Issues table, Cortex Cloud automatically does the following:

  • Disables any IOC rules that reach 5000 or more hits over 24 hours.

  • Creates a rule exception based on the PROCESS SHA256 field for IOC rules that hit more than 100 endpoints over 72 hours.

  1. In Threat ManagementDetection RulesIOC, select + Add IOC.

  2. Configure the IOC criteria.

  3. (Optional) Define any expiration criteria for your IOC rules.

    You can also configure additional expiration criteria per IOC type to apply to all IOC rules of that type. In most cases, IOC types like Destination IP or Host Name are considered malicious only for a short period of time since they are soon cleaned and then used by legitimate services, from which time they only cause false positives. For these types of IOCs, you can set a defined expiration period. The expiration criteria you define for an IOC type will apply to all existing rules and additional rules that you create in the future. By default, Cortex Cloud does not apply an expiration date set on IOCs.

    1. Select Default Rule Expiration.

    2. Set the expiration for any relevant IOC type. Options are Never, 7 Days, 30 days, 90 days, or 180 days.

    3. Click Save.