Manage your behavioral indicator of compromise (BIOC) rules in **Threat Management** → **Detection Rules** → **BIOC**.
If you are assigned a role that enables **Investigation** → **Rules** privileges, you can view all user-defined and preconfigured rules for behavioral indicators of compromise (BIOCs).
If you have Cortex XSIAM Analytics enabled, you can also view Analytics BIOCs (ABIOCs) on a separate page. To access this page, click **Analytics BIOC Rules** next to the refresh icon at the top of the page.
Each page displays fields that are relevant to the specific rule type.
### BIOC rule fields
By default, the **BIOC Rules** page displays all enabled rules. To search for a specific rule, use the filters above the results table to narrow the results. You can also manage existing rules using the right-click pivot menu.
The following table describes the fields that are available for each BIOC rule in alphabetical order.
| Field | Description |
| ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **# OF ISSUES** | The number of incidents generated by this rule. |
| **BACKWARDS SCAN STATUS** | Status of the Cortex XSIAM search for the first 10,000 matches when the BIOC rule was created or edited. Status can be: - Done - Failed - Pending - Queued |
| **BACKWARDS SCAN TIMESTAMP** | Timestamp of the Cortex XSIAM search for the first 10,000 matches in your Cortex XSIAM when the BIOC rule was created or edited. |
| **BACKWARDS SCAN RETRIES** | Number of times Cortex XSIAM searched for the first 10,000 matches in your Cortex XSIAM when the BIOC rule was created or edited. |
| **BEHAVIOR** | A schematic of the behavior of the rule. |
| **COMMENT** | Free-form comments specified when the BIOC was created or modified. |
| **EXCEPTIONS** | Exceptions to the BIOC rule. When there's a match on the exception, the event will not generate an incident. |
| **GLOBAL RULE ID** | Unique identification number assigned to rules created by Palo Alto Networks. |
| **INSERTION DATE** | Date and time when the BIOC rule was created. |
| **MITRE ATT&CK TACTIC** | Displays the type of MITRE ATT&CK tactic the BIOC rule is attempting to trigger on. |
| **MITRE ATT&CK TECHNIQUE** | Displays the type of MITRE ATT&CK technique and sub-technique the BIOC rule is attempting to trigger on. |
| **MODIFICATION DATE** | Date and time when the BIOC was last modified. |
| **NAME** | Unique name that describes the rule. Global BIOC rules defined by Palo Alto Networks are indicated with a blue dot and cannot be modified or deleted. |
| **RULE ID** | Unique identification number for the rule. |
| **TYPE** | Type of BIOC rule: - Collection - Credential Access - Dropper - Evasion - Execution - Evasive - Exfiltration - File Privilege Manipulation - File Type Obfuscation - Infiltration - Lateral Movement - Other - Persistence - Privilege Escalation - Reconnaissance - Tampering |
| **SEVERITY** | BIOC severity that was defined when the BIOC was created. |
| **SOURCE** | User who created this BIOC, the file name from which it was created, or Palo Alto Networks if delivered through content updates. |
| **STATUS** | - Enabled - Partially Enabled (Agent Disabled) - Partially Enabled (Server Disabled) - Disabled When you hover over a rule that's disabled, a pop-up message appears to provide more information about the Disable action. |
| **USED IN PROFILES** | Displays if the BIOC rule is associated with a Restriction profile. |
### Analytics BIOC rule fields
By default, the **Analytics BIOC Rules** page displays all enabled rules. To search for a specific rule, use the filters above the results table to narrow the results. You can also disable and enable rules using the right-click pivot menu.
The following table describes the fields that are available for each Analytics BIOC rule in alphabetical order.
| Field | Description |
| ---------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Activation Prerequisites** | Displays a description of the prerequisites Cortex XSIAM requires in order to activate the rule. |
| **Description** | Description of the behavior that will generate the issue. |
| **# OF HITS** | The number of hits (matches) on this rule. |
| **NAME** | Unique name that describes the rule. New rules are identified with a blue badge icon. |
| **SEVERITY** | BIOC severity that was defined when the BIOC rule was created. Severity levels can be **Low**, **Medium**, **High**, **Critical**, and **Multiple**. **Multiple** severity BIOC rules can generat incidents with different severity levels. Hover over the flag to see the severities defined for the rule. |
| **STATUS** | Displays whether the rule is **Enabled**, **Disabled**, or **Pending Activation**. Rules that are **Pending Activation** are in the process of collecting the data required to enable the rule. Hover over the field to view how much data has already been collected within a certain period of time. |
| **TAGS** | Filter the results according to **Detector Tags**. This tag enables you to filter for specific detectors such as Identity Threat, Identity Analytics, and others. |