<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Forensics Addon - Best practise licence and usage in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forensics-addon-best-practise-licence-and-usage/m-p/503895#M2202</link>
    <description>&lt;P&gt;Hello dear community,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how do we use this addon?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had found a article about the forensics addon which said, you can also put this feature to an client/server after the incident etc. happened.&lt;/P&gt;&lt;P&gt;What is the difference between having this addon for all our servers/clients active or to put this profile to our client/server after a real incident which needs a forensic investigation to dig deeper.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How and when does the addon pull the forensic logs, when clients are offline and they get online only for 8 hours? Does it happen when the client is turned on?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We do really want to know if we need to buy more licences for this addon or if it is not neccasarry.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Jun 2022 18:55:06 GMT</pubDate>
    <dc:creator>RFeyertag</dc:creator>
    <dc:date>2022-06-15T18:55:06Z</dc:date>
    <item>
      <title>Forensics Addon - Best practise licence and usage</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forensics-addon-best-practise-licence-and-usage/m-p/503895#M2202</link>
      <description>&lt;P&gt;Hello dear community,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how do we use this addon?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had found a article about the forensics addon which said, you can also put this feature to an client/server after the incident etc. happened.&lt;/P&gt;&lt;P&gt;What is the difference between having this addon for all our servers/clients active or to put this profile to our client/server after a real incident which needs a forensic investigation to dig deeper.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How and when does the addon pull the forensic logs, when clients are offline and they get online only for 8 hours? Does it happen when the client is turned on?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We do really want to know if we need to buy more licences for this addon or if it is not neccasarry.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 18:55:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forensics-addon-best-practise-licence-and-usage/m-p/503895#M2202</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-06-15T18:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: Forensics Addon - Best practise licence and usage</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forensics-addon-best-practise-licence-and-usage/m-p/504020#M2208</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;this boils down to the decision that your management team makes. What customers typically do is to procure an adequate number of Forensics licenses that should cover the count of endpoints that need to be triaged during an incident. That exact number depends on your internal teams based on experience.&lt;BR /&gt;&lt;BR /&gt;Like any process, the XDR Forensics capability can only run when an endpoint is in a power-on state. You can perform an online triage by making the appropriate changes in the corresponding Agent Settings profile and initiating an online triage.&lt;/P&gt;&lt;P&gt;I also believe you're referring to the possibility of an Offline triage here. You can create a Forensics Collector and deploy it on an endpoint manually to collect Forensics evience as well. Once the collection is complete, the zip file can be uploaded to the XDR console for further analysis.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 02:52:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forensics-addon-best-practise-licence-and-usage/m-p/504020#M2208</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-06-16T02:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: Forensics Addon - Best practise licence and usage</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forensics-addon-best-practise-licence-and-usage/m-p/505489#M2250</link>
      <description>&lt;P&gt;From point of the technical aspect, I have no clue how the process can be in a real life scenario. Is there any ressource existing, where we can ask how to setup our Cortex XDR for a good practise way belonging to forensics incidents? I know in the end, we will have a team of forensics persons in the house, which will need informations quick. Therefore I thought we will collect every day forensics data from all endpoints.&lt;/P&gt;&lt;P&gt;To divide them to endpoint forensic and endpoint non forensic is not solved well. I would like to see a type of tag to be more flexible without putting the client/server to another endpoint group/policy/profile and dividing the inventory.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So now for my understanding, the triage is the function, which collects all forensic data based on the agent settings to the console/Host Timeline? When the collector in the agent settings is set to 12 hours, what will haben with this data? Is it collected, but the clients needs triage flag to get the informations to the host Timeline?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 20:20:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forensics-addon-best-practise-licence-and-usage/m-p/505489#M2250</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-06-22T20:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: Forensics Addon - Best practise licence and usage</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forensics-addon-best-practise-licence-and-usage/m-p/506738#M2294</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adding perspective on this question as one of my customer had this process:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1st --&amp;gt; isolated the potential compromise endpoint (&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/response-actions/isolate-an-endpoint" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/response-actions/isolate-an-endpoint&lt;/A&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2nd --&amp;gt; assign agent profile with forensic enable (step 10--&amp;gt;item 4 --&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/customizable-agent-settings/add-agent-settings-profile" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/customizable-agent-settings/add-agent-settings-profile&lt;/A&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3rd --&amp;gt; wait 24hrs to collect all forensic data (can be customize to lower hrs)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4th --&amp;gt; once data is available, start triage.. (&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/forensics/forensics-add-on-options" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/forensics/forensics-add-on-options&lt;/A&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Below are additional info on forensics:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/forensics" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/forensics&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 15:08:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forensics-addon-best-practise-licence-and-usage/m-p/506738#M2294</guid>
      <dc:creator>jcandelaria</dc:creator>
      <dc:date>2022-06-28T15:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: Forensics Addon - Best practise licence and usage</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forensics-addon-best-practise-licence-and-usage/m-p/506913#M2297</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;to answer your question on creating groups/tags for Forensics, the reasoning is that when an endpoint is flagged for Forensics investigation, it is a potential case of assumed compromise. The endpoint should be ideally isolated to prevent any artefacts from being modified or destroyed in the host, or lateral movement/exfiltration etc. Assigning them to a specific logical partition using tags/groups is the recommended method to ensure the integrity of the forensics activities are maintained.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Surely, you can collect Forensics for all endpoints - however that'd be a huge volume of data collected every day and you'd need to procure additional licenses to ensure all your endpoints are covered, and additional personnel to comb through all of that. You can discuss with your DFIR teams to understand if all endpoints need to be actively covered and how it impact your operations. Existing processes/playbooks are a good way to set a baseline.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can consider one of the following for creating logical groups for Forensics:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Method A (using endpoint tags)&lt;/U&gt;&lt;/P&gt;&lt;P&gt;1. assign user-created tags to specific endpoints as specified in the documentation&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/manage-cortex-xdr-agents/manage-endpoint-tags" target="_blank"&gt;here&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_0-1656465627272.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42037i260EAB9C2302DE0D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="bbarmanroy_0-1656465627272.png" alt="bbarmanroy_0-1656465627272.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;2. You can define endpoint policies based on the user-created tags like so and apply corresponding endpoint profiles with Forensics enabled:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_1-1656465721735.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42038iAA6DD8F5359DC6AF/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_1-1656465721735.png" alt="bbarmanroy_1-1656465721735.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Method 2 (using static groups)&lt;/U&gt;&lt;/P&gt;&lt;P&gt;You can refer to the documentation &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/define-endpoint-groups" target="_blank"&gt;here&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/174003"&gt;@jcandelaria&lt;/a&gt;&amp;nbsp;has provided you with the links for optimizing your workflows.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 01:35:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forensics-addon-best-practise-licence-and-usage/m-p/506913#M2297</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-06-29T01:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Forensics Addon - Best practise licence and usage</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forensics-addon-best-practise-licence-and-usage/m-p/540533#M4248</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt;&amp;nbsp;&amp;amp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/174003"&gt;@jcandelaria&lt;/a&gt;!&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot for your informations to the process of DFIR.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the right way to do offline triage, simply case is when the network is locked down?&lt;/P&gt;
&lt;P&gt;In my offline triage test I tested now, the installed cortex agent blocked the triage process because there was dropped a vulnerable driver. So, what do you recommend here? Will this also&amp;nbsp;happen in the online/manual triage?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried following steps (first the offline triage-configuration with heavy and memory collection):&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forensics-add-on-how-to-get-the-most-out-of-it/td-p/539422" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forensics-add-on-how-to-get-the-most-out-of-it/td-p/539422&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;BR /&gt;&lt;BR /&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Apr 2023 13:57:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forensics-addon-best-practise-licence-and-usage/m-p/540533#M4248</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-04-29T13:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Forensics Addon - Best practise licence and usage</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forensics-addon-best-practise-licence-and-usage/m-p/542100#M4347</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;I am sorry I missed out on your message. Is the issue of vulnerable driver still persistent? If so, please raise a support ticket with the relevant information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To answer your first question, the difference between online and offline triage are the following&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;online forensics consumes one license from your quota of forensics licenses&lt;/LI&gt;
&lt;LI&gt;online triage will continuously keep collecting forensic artefacts and send it to XDR, whereas you'd need to manually run and upload the collected evidence to XDR (point-in-time snapshot of forensic evidence).&lt;/LI&gt;
&lt;LI&gt;If the endpoint is isolated with XDR, the online forensic collection capability will still work. That is not applicable for offline forensics as you'd need to manually upload the collected evidence.&lt;/LI&gt;
&lt;LI&gt;Offline triage is typically used in cases when the endpoint has been completely removed from the network and is "truly" offline, or put in a firewalled segment with no access to other devices, or something along those lines. It requires more work, and such runbooks are typically defined internally within the organization.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 15 May 2023 02:34:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/forensics-addon-best-practise-licence-and-usage/m-p/542100#M4347</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2023-05-15T02:34:57Z</dc:date>
    </item>
  </channel>
</rss>

