<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Integrating VirusTotal with Cortex XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-virustotal-with-cortex-xdr/m-p/536599#M3948</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/279936"&gt;@arjun_weeknd&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Cortex XDR does not upload any information to Virus Total. Cortex XDR does exactly what you do, query VT for hash, domain, ip, etc and shows you the result, if any, for each of the artifacts in the XDR incident.&lt;/P&gt;</description>
    <pubDate>Mon, 27 Mar 2023 13:14:39 GMT</pubDate>
    <dc:creator>fmoixsante</dc:creator>
    <dc:date>2023-03-27T13:14:39Z</dc:date>
    <item>
      <title>Integrating VirusTotal with Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-virustotal-with-cortex-xdr/m-p/536565#M3943</link>
      <description>&lt;P&gt;Hi Guys,&lt;BR /&gt;In the Artifacts section we are not able to see the VT Score . For this we are manually copying the IP's , Hashes &amp;amp; viewing in the Virustotal console.&lt;BR /&gt;Got to know we need to configure the API key but the concern is what data does Cortex XDR submit to VT ?&lt;BR /&gt;only hashes , IP's or it will upload the entire file ?&lt;BR /&gt;What are the precautions/best practices we need to take &amp;amp; does Cortex submits any sensitive data to&amp;nbsp; Virustotal&amp;nbsp; ?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 08:25:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-virustotal-with-cortex-xdr/m-p/536565#M3943</guid>
      <dc:creator>arjun_weeknd</dc:creator>
      <dc:date>2023-03-27T08:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating VirusTotal with Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-virustotal-with-cortex-xdr/m-p/536599#M3948</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/279936"&gt;@arjun_weeknd&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Cortex XDR does not upload any information to Virus Total. Cortex XDR does exactly what you do, query VT for hash, domain, ip, etc and shows you the result, if any, for each of the artifacts in the XDR incident.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 13:14:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-virustotal-with-cortex-xdr/m-p/536599#M3948</guid>
      <dc:creator>fmoixsante</dc:creator>
      <dc:date>2023-03-27T13:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating VirusTotal with Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-virustotal-with-cortex-xdr/m-p/1247308#M9089</link>
      <description>&lt;P&gt;The issue with the Cortex XDR and VirusTotal integration is that Cortex queries VirusTotal for all IOCs (hashes, URLs, and domains) — including internal ones.&lt;BR /&gt;As a result, internal server names can end up being publicly visible on VirusTotal. Palo Alto Networks support has confirmed this behavior.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 10:49:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-virustotal-with-cortex-xdr/m-p/1247308#M9089</guid>
      <dc:creator>VRubio</dc:creator>
      <dc:date>2026-02-03T10:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating VirusTotal with Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-virustotal-with-cortex-xdr/m-p/1250442#M9197</link>
      <description>&lt;P&gt;Is there any updates for this behavior&amp;gt; internal names can end up...&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2026 11:43:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-virustotal-with-cortex-xdr/m-p/1250442#M9197</guid>
      <dc:creator>T.Nurmi</dc:creator>
      <dc:date>2026-03-18T11:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating VirusTotal with Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-virustotal-with-cortex-xdr/m-p/1250466#M9201</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;The issue number you can follow with Cortex support is CRTX-225799.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2026 18:13:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/integrating-virustotal-with-cortex-xdr/m-p/1250466#M9201</guid>
      <dc:creator>VRubio</dc:creator>
      <dc:date>2026-03-18T18:13:11Z</dc:date>
    </item>
  </channel>
</rss>

