BIOC rule details

Manage your behavioral indicator of compromise (BIOC) rules in Threat ManagementDetection RulesBIOC.

If you are assigned a role that enables InvestigationRules privileges, you can view all user-defined and preconfigured rules for behavioral indicators of compromise (BIOCs).

If you have Cortex XSIAM Analytics enabled, you can also view Analytics BIOCs (ABIOCs) on a separate page. To access this page, click Analytics BIOC Rules next to the refresh icon at the top of the page.

Each page displays fields that are relevant to the specific rule type.

BIOC rule fields

By default, the BIOC Rules page displays all enabled rules. To search for a specific rule, use the filters above the results table to narrow the results. You can also manage existing rules using the right-click pivot menu.

The following table describes the fields that are available for each BIOC rule in alphabetical order.

Field Description
# OF ISSUES The number of incidents generated by this rule.
BACKWARDS SCAN STATUS Status of the Cortex XSIAM search for the first 10,000 matches when the BIOC rule was created or edited. Status can be: - Done - Failed - Pending - Queued
BACKWARDS SCAN TIMESTAMP Timestamp of the Cortex XSIAM search for the first 10,000 matches in your Cortex XSIAM when the BIOC rule was created or edited.
BACKWARDS SCAN RETRIES Number of times Cortex XSIAM searched for the first 10,000 matches in your Cortex XSIAM when the BIOC rule was created or edited.
BEHAVIOR A schematic of the behavior of the rule.
COMMENT Free-form comments specified when the BIOC was created or modified.
EXCEPTIONS Exceptions to the BIOC rule. When there's a match on the exception, the event will not generate an incident.
GLOBAL RULE ID Unique identification number assigned to rules created by Palo Alto Networks.
INSERTION DATE Date and time when the BIOC rule was created.
MITRE ATT&CK TACTIC Displays the type of MITRE ATT&CK tactic the BIOC rule is attempting to trigger on.
MITRE ATT&CK TECHNIQUE Displays the type of MITRE ATT&CK technique and sub-technique the BIOC rule is attempting to trigger on.
MODIFICATION DATE Date and time when the BIOC was last modified.
NAME Unique name that describes the rule. Global BIOC rules defined by Palo Alto Networks are indicated with a blue dot and cannot be modified or deleted.
RULE ID Unique identification number for the rule.
TYPE Type of BIOC rule: - Collection - Credential Access - Dropper - Evasion - Execution - Evasive - Exfiltration - File Privilege Manipulation - File Type Obfuscation - Infiltration - Lateral Movement - Other - Persistence - Privilege Escalation - Reconnaissance - Tampering
SEVERITY BIOC severity that was defined when the BIOC was created.
SOURCE User who created this BIOC, the file name from which it was created, or Palo Alto Networks if delivered through content updates.
STATUS - Enabled - Partially Enabled (Agent Disabled) - Partially Enabled (Server Disabled) - Disabled When you hover over a rule that's disabled, a pop-up message appears to provide more information about the Disable action.
USED IN PROFILES Displays if the BIOC rule is associated with a Restriction profile.

Analytics BIOC rule fields

By default, the Analytics BIOC Rules page displays all enabled rules. To search for a specific rule, use the filters above the results table to narrow the results. You can also disable and enable rules using the right-click pivot menu.

The following table describes the fields that are available for each Analytics BIOC rule in alphabetical order.

Field Description
Activation Prerequisites Displays a description of the prerequisites Cortex XSIAM requires in order to activate the rule.
Description Description of the behavior that will generate the issue.
# OF HITS The number of hits (matches) on this rule.
NAME Unique name that describes the rule. New rules are identified with a blue badge icon.
SEVERITY BIOC severity that was defined when the BIOC rule was created. Severity levels can be Low, Medium, High, Critical, and Multiple. Multiple severity BIOC rules can generat incidents with different severity levels. Hover over the flag to see the severities defined for the rule.
STATUS Displays whether the rule is Enabled, Disabled, or Pending Activation. Rules that are Pending Activation are in the process of collecting the data required to enable the rule. Hover over the field to view how much data has already been collected within a certain period of time.
TAGS Filter the results according to Detector Tags. This tag enables you to filter for specific detectors such as Identity Threat, Identity Analytics, and others.