After you create an indicator rule, you can take the following actions:
Note
For Analytics BIOC rules, you can only disable and enable rules.
View Alerts Triggered by a Rule
As your IOC and BIOC rules trigger alerts, Cortex XDR displays the total # OF HITS for the rule in the the BIOC or IOC rules page. For rules with a high, medium, or low severity that have raised one or more alerts, you can quickly pivot to a filtered view of those alerts raised by the indicator:
Select BIOC or IOC).
→ and the type of rule (Right-click anywhere in a rule, and then select View associated alerts.
You can see a filtered query of alerts associated with the Rule ID.
Use a BIOC Rule as the Basis of a Query
Select BIOC or IOC).
→ and the type of rule (Right-click anywhere in the rule, and then select Open in query builder.
populates a query using the criteria of the BIOC rule.
If desired, add or change the query criteria.
(Optional) Test your query to see the sample results.
If you are satisfied with query, Save the query.
For more information, see Manage Your Queries.
Edit a Rule
After you create a rule, it may be necessary to tweak or change the rule settings. You can open the rule configuration from the Rules page or from the pivot menu of an alert triggered by the rule. To edit the rule from the Rules page:
Select BIOC or IOC).
→ and the type of rule (Locate the rule you want to edit.
Right-click anywhere in the rule and select Edit.
Edit the rule settings as needed, and then click OK.
If you make any changes, Test and then Save the rule.
Export a Rule (BIOC Only)
Select
→ → .Select the rules that you want to export.
Right-click any of the rows, and select Export selected.
The exported file is not editable, however, you can use it as a source to import rules at a later date.
Copy a BIOC Rule
You can use an existing rule as a template to create a new one. Global BIOC rules cannot be deleted or altered, but you can copy a global rule and edit the copy.
From Cortex XDR, select → and then BIOC.
Locate the rule you want to copy.
Right-click anywhere in the rule row and then select Save as New to create a duplicate rule.
Disable or Remove a Rule
If you no longer need a rule you can temporarily disable or permanently remove it.
Note
You cannot delete global BIOCs delivered with content updates.
Select BIOC or IOC).
→ and the type of rule (Locate the rule that you want to change.
Right-click anywhere in the rule row and then select Remove to permanently delete the rule, or Disable to temporarily stop the rule. If you disable a rule you can later return to the rule page to Enable it.