Edit, export, copy, disable, or remove rules, and add rule exceptions for existing indicators in Cortex XDR.
After you create an indicator rule, you can take the following actions:
Note
For Analytics BIOC rules, you can only disable and enable rules.
View Alerts Triggered by a Rule
As your IOC and BIOC rules trigger alerts, Cortex XDR displays the total # OF HITS for the rule in the the BIOC or IOC rules page. For rules with a high, medium, or low severity that have raised one or more alerts, you can quickly pivot to a filtered view of those alerts raised by the indicator:
Select BIOC or IOC).
→ and the type of rule (Right-click anywhere in a rule, and then select View associated alerts.
You can see a filtered query of alerts associated with the Rule ID.
Use a BIOC Rule as the Basis of a Query
Select BIOC or IOC).
→ and the type of rule (Right-click anywhere in the rule, and then select Open in query builder.
populates a query using the criteria of the BIOC rule.
If desired, add or change the query criteria.
(Optional) Test your query to see the sample results.
If you are satisfied with query, Save the query.
For more information, see Manage Your Queries.
Edit a Rule
After you create a rule, it may be necessary to tweak or change the rule settings. You can open the rule configuration from the Rules page or from the pivot menu of an alert triggered by the rule. To edit the rule from the Rules page:
Select BIOC or IOC).
→ and the type of rule (Locate the rule you want to edit.
Right-click anywhere in the rule and select Edit.
Edit the rule settings as needed, and then click OK.
If you make any changes, Test and then Save the rule.
Export a Rule (BIOC Only)
Select
→ → .Select the rules that you want to export.
Right-click any of the rows, and select Export selected.
The exported file is not editable, however, you can use it as a source to import rules at a later date.
Copy a BIOC Rule
You can use an existing rule as a template to create a new one. Global BIOC rules cannot be deleted or altered, but you can copy a global rule and edit the copy.
From Cortex XDR, select → and then BIOC.
Locate the rule you want to copy.
Right-click anywhere in the rule row and then select Save as New to create a duplicate rule.
Disable or Remove a Rule
If you no longer need a rule you can temporarily disable or permanently remove it.
Note
You cannot delete global BIOCs delivered with content updates.
Select BIOC or IOC).
→ and the type of rule (Locate the rule that you want to change.
Right-click anywhere in the rule row and then select Remove to permanently delete the rule, or Disable to temporarily stop the rule. If you disable a rule you can later return to the rule page to Enable it.
Partially Disable or Re-enable a BIOC Rule
You can disable one or more BIOC rules on the agent, on the server, or on both. This provides you more granularity for managing the prevention actions triggered by the BIOC Rules.
From Cortex XDR, select → .
Select the rules you want to disable.
Right-click any of the rules and select to disable the rules on the agent, on the server, or on both.
Note
For BIOC rules that are applied to prevention profiles:
If you disable a rule only on the agent, detection on the server works as usual.
If you disable a rule only on the server, prevention on the agent works as usual.
We recommend you supply a reason for disabling the rule.
Note
When a BIOC rule is disabled automatically by Cortex XDR, for example due to the server anti flooding mechanism, prevention on the agent works as before.
You can re-enable a rule granularly for detection, prevention, or both in the same way.