For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex Cloud Runtime

View generating BIOC or IOC rule

View the BIOC or IOC rule that generated an issue.

You can easily view and edit the BIOC and IOC rules that generated issues directly from the Issues table:

  1. From the Issues page, locate issues with Detection methods: XDR BIOC and XDR IOC.

  2. Right-click the row, and select Manage Issue → View generating rule.

    Cortex Cloud opens the BIOC rule that generated the issue in the BIOC Rules page. If the rule has been deleted, an empty table is displayed.

  3. Review the rule, if necessary, right-click to perform available actions.

Last updated

Was this helpful?