Manage IOC and BIOC rules - Edit, export, copy, disable, or remove rules, and add rule exceptions for existing indicators in Cortex XDR. - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR 5.x Documentation

Product
Cortex XDR
License
XDR + Cloud
Creation date
2025-07-13
Last date published
2026-06-11
Category
Administrator Guide
Abstract

Edit, export, copy, disable, or remove rules, and add rule exceptions for existing indicators in Cortex XDR.

After you create an indicator rule, you can take the following actions:

Note

For Analytics BIOC rules, you can only disable and enable rules.

As your IOC and BIOC rules generate issues, Cortex XDR displays the total # OF ALERTS generated by the rule in the the BIOC or IOC rules page. For rules with a high, medium, or low severity that have generated one or more issues, you can quickly pivot to a filtered view of those issues generated by the indicator:

  1. Select Threat ManagementDetection Rules and the type of rule (BIOC or IOC).

  2. Right-click anywhere in a rule, and then select View associated issues.

    You can view a filtered query of issues associated with the Rule ID.

  1. Select Detection & Threat IntelDetection Rules and the type of rule (BIOC or IOC).

  2. Right-click anywhere in the rule, and then select Open in query builder.

    Cortex XDR populates a query using the criteria of the BIOC rule.

  3. Add or change the query criteria as required.

  4. (Optional) Test your query to see the sample results.

  5. If you are satisfied with the query, Save it.

    For more information, see Edit and run queries in Query Center.

After you create a rule, it may be necessary to tweak or change the rule settings. You can open the rule configuration from the Rules page or from the pivot menu of an issue generated by the rule. To edit the rule from the Rules page:

  1. Select Threat ManagementDetection Rules and the type of rule (BIOC or IOC).

  2. Locate the rule you want to edit.

  3. Right-click anywhere in the rule and select Edit.

  4. Edit the rule settings as needed, and then click OK.

    If you make any changes, Test and then Save the rule.

  1. Select Threat ManagementDetection RulesBIOC.

  2. Select the rules that you want to export.

  3. Right-click any of the rows, and select Export selected.

    The exported file is not editable, however, you can use it as a source to import rules at a later date.

You can use an existing rule as a template to create a new one. Global BIOC rules cannot be deleted or altered, but you can copy a global rule and edit the copy.

  1. Select Threat ManagementDetection Rules and then BIOC.

  2. Locate the rule you want to copy.

  3. Right-click anywhere in the rule row and then select Save as New to create a duplicate rule.

If you no longer need a rule you can temporarily disable or permanently remove it.

Note

You cannot delete global BIOCs delivered with content updates.

  1. Select Threat ManagementDetection Rules and the type of rule (BIOC or IOC).

  2. Locate the rule that you want to change.

  3. Right-click anywhere in the rule row and then select Remove to permanently delete the rule, or Disable to temporarily stop the rule. If you disable a rule you can later return to the rule page to Enable it.

You can disable one or more BIOC rules on the agent, on the server, or on both. This provides you more granularity for managing the prevention actions generated by the BIOC Rules.

  1. Navigate to Threat ManagementDetection RulesBIOC.

  2. Select the rules you want to disable.

  3. Right-click any of the rules and select to disable the rules on the agent, on the server, or on both.

    Note

    For BIOC rules that are applied to prevention profiles:

    • If you disable a rule only on the agent, detection on the server works as usual.

      If you disable a rule only on the server, prevention on the agent works as usual.

  4. We recommend you supply a reason for disabling the rule.

Note

When a BIOC rule is disabled automatically by Cortex XDR, for example due to the server anti flooding mechanism, prevention on the agent works as before.

You can re-enable a rule granularly for detection, prevention, or both in the same way.