> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-bioc/bioc-rule-details.md).

# BIOC rule details

{% hint style="info" %}

### Notice

Managing BIOCs requires a Cortex XDR Pro license.
{% endhint %}

Manage your behavioral indicator of compromise (BIOC) rules in **Detection Rules** → **BIOC**.

If you are assigned a role that enables **Investigation** → **Rules** privileges, you can view all user-defined and preconfigured rules for behavioral indicators of compromise (BIOCs).

If you have Cortex XDR Analytics enabled, you can also view Analytics BIOCs (ABIOCs) on a separate page. To access this page, click **Analytics BIOC Rules** next to the refresh icon at the top of the page.

Each page displays fields that are relevant to the specific rule type.

<details>

<summary>BIOC rule fields</summary>

By default, the **BIOC Rules** page displays all enabled rules. To search for a specific rule, use the filters above the results table to narrow the results. You can also manage existing rules using the right-click pivot menu.

The following table describes the fields that are available for each BIOC rule in alphabetical order.

| Field                        | Description                                                                                                                                                                                                                                                                                                                                                                                    |
| ---------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **# OF ALERTS**              | The number of alerts triggered by this rule.                                                                                                                                                                                                                                                                                                                                                   |
| **BACKWARDS SCAN STATUS**    | <p>Status of the Cortex XDR search for the first 10,000 matches when the BIOC rule was created or edited. Status can be:</p><ul><li>Done</li><li>Failed</li><li>Pending</li><li>Queued</li></ul>                                                                                                                                                                                               |
| **BACKWARDS SCAN TIMESTAMP** | Timestamp of the Cortex XDR search for the first 10,000 matches in your Cortex XDR when the BIOC rule was created or edited.                                                                                                                                                                                                                                                                   |
| **BACKWARDS SCAN RETRIES**   | Number of times Cortex XDR searched for the first 10,000 matches in your Cortex XDR when the BIOC rule was created or edited.                                                                                                                                                                                                                                                                  |
| **BEHAVIOR**                 | A schematic of the behavior of the rule.                                                                                                                                                                                                                                                                                                                                                       |
| **COMMENT**                  | Free-form comments specified when the BIOC was created or modified.                                                                                                                                                                                                                                                                                                                            |
| **EXCEPTIONS**               | Exceptions to the BIOC rule. When there's a match on the exception, the event will not trigger an alert.                                                                                                                                                                                                                                                                                       |
| **GLOBAL RULE ID**           | Unique identification number assigned to rules created by Palo Alto Networks.                                                                                                                                                                                                                                                                                                                  |
| **INSERTION DATE**           | Date and time when the BIOC rule was created.                                                                                                                                                                                                                                                                                                                                                  |
| **MITRE ATT\&CK TACTIC**     | Displays the type of MITRE ATT\&CK tactic the BIOC rule is attempting to trigger on.                                                                                                                                                                                                                                                                                                           |
| **MITRE ATT\&CK TECHNIQUE**  | Displays the type of MITRE ATT\&CK technique and sub-technique the BIOC rule is attempting to trigger on.                                                                                                                                                                                                                                                                                      |
| **MODIFICATION DATE**        | Date and time when the BIOC was last modified.                                                                                                                                                                                                                                                                                                                                                 |
| **NAME**                     | Unique name that describes the rule. Global BIOC rules defined by Palo Alto Networks are indicated with a blue dot and cannot be modified or deleted.                                                                                                                                                                                                                                          |
| **RULE ID**                  | Unique identification number for the rule.                                                                                                                                                                                                                                                                                                                                                     |
| **TYPE**                     | <p>Type of BIOC rule:</p><ul><li>Collection</li><li>Credential Access</li><li>Dropper</li><li>Evasion</li><li>Execution</li><li>Evasive</li><li>Exfiltration</li><li>File Privilege Manipulation</li><li>File Type Obfuscation</li><li>Infiltration</li><li>Lateral Movement</li><li>Other</li><li>Persistence</li><li>Privilege Escalation</li><li>Reconnaissance</li><li>Tampering</li></ul> |
| **SEVERITY**                 | BIOC severity that was defined when the BIOC was created.                                                                                                                                                                                                                                                                                                                                      |
| **SOURCE**                   | User who created this BIOC, the file name from which it was created, or Palo Alto Networks if delivered through content updates.                                                                                                                                                                                                                                                               |
| **STATUS**                   | <ul><li>Enabled</li><li>Partially Enabled (Agent Disabled)</li><li>Partially Enabled (Server Disabled)</li><li>Disabled</li></ul><p>When you hover over a rule that's disabled, a pop-up message appears to provide more information about the Disable action.</p>                                                                                                                             |
| **USED IN PROFILES**         | Displays if the BIOC rule is associated with a Restriction profile.                                                                                                                                                                                                                                                                                                                            |

</details>

<details>

<summary>Analytics BIOC rule fields</summary>

By default, the **Analytics BIOC Rules** page displays all enabled rules. To search for a specific rule, use the filters above the results table to narrow the results. You can also disable and enable rules using the right-click pivot menu.

The following table describes the fields that are available for each Analytics BIOC rule in alphabetical order.

| Field                        | Description                                                                                                                                                                                                                                                                                                                                                                                       |
| ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Activation Prerequisites** | Displays a description of the prerequisites Cortex XDR requires in order to activate the rule.                                                                                                                                                                                                                                                                                                    |
| **Description**              | Description of the behavior that will raise the alert.                                                                                                                                                                                                                                                                                                                                            |
| **# OF HITS**                | The number of hits (matches) on this rule.                                                                                                                                                                                                                                                                                                                                                        |
| **NAME**                     | Unique name that describes the rule. New rules are identified with a blue badge icon.                                                                                                                                                                                                                                                                                                             |
| **SEVERITY**                 | <p>BIOC severity that was defined when the BIOC rule was created. Severity levels can be <strong>Low</strong>, <strong>Medium</strong>, <strong>High</strong>, <strong>Critical</strong>, and <strong>Multiple</strong>.</p><p><strong>Multiple</strong> severity BIOC rules can raise alerts with different severity levels. Hover over the flag to see the severities defined for the rule.</p> |
| **STATUS**                   | <p>Displays whether the rule is <strong>Enabled</strong>, <strong>Disabled</strong>, or <strong>Pending Activation</strong>.</p><p>Rules that are <strong>Pending Activation</strong> are in the process of collecting the data required to enable the rule. Hover over the field to view how much data within a certain period of time has already been collected.</p>                           |
| **TAGS**                     | Filter the results according to **Detector Tags**. This tag enables you to filter for specific detectors such as Identity Threat, Identity Analytics, and others.                                                                                                                                                                                                                                 |

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-bioc/bioc-rule-details.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
