<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Incident Best Practices in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-best-practices/m-p/537113#M3996</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/262810"&gt;@Jeroen_Proost&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Thank you for writing to live community. This indeed sounds like a very broad subject. Do you think you can elaborate a bit on what you mean or what you're hoping to achieve?&lt;BR /&gt;&lt;BR /&gt;This can be taken in multiple different directions - &lt;A href="about:blank" target="_self"&gt;alert tunings,&amp;nbsp;&lt;/A&gt;&lt;A href="http://&amp;lt;iframe%20width=&amp;quot;600&amp;quot; height=&amp;quot;338&amp;quot; src=&amp;quot;https://www.youtube.com/embed/4MAtHYsbl6s&amp;quot; title=&amp;quot;SOC Analysts - Understanding Incident Resources&amp;quot; frameborder=&amp;quot;0&amp;quot; allow=&amp;quot;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share&amp;quot; allowfullscreen&amp;gt;&amp;lt;/iframe&amp;gt;" target="_self"&gt;incident sources&lt;/A&gt;,&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics-Concepts" target="_self"&gt;analytics detection time intervals.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Mar 2023 14:42:15 GMT</pubDate>
    <dc:creator>mavraham</dc:creator>
    <dc:date>2023-03-30T14:42:15Z</dc:date>
    <item>
      <title>Cortex XDR Incident Best Practices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-best-practices/m-p/537110#M3995</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I know this migth not easy to answer, but I'm going to take my chance anyway.&lt;BR /&gt;Are there any incident best practices for (each) Cortex XDR detector&amp;nbsp;documented ? For example what a certain detector means, what the best thing is to do in this case, ...&lt;BR /&gt;&lt;BR /&gt;Thank you very much,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 14:10:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-best-practices/m-p/537110#M3995</guid>
      <dc:creator>Jeroen_Proost</dc:creator>
      <dc:date>2023-03-30T14:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Incident Best Practices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-best-practices/m-p/537113#M3996</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/262810"&gt;@Jeroen_Proost&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Thank you for writing to live community. This indeed sounds like a very broad subject. Do you think you can elaborate a bit on what you mean or what you're hoping to achieve?&lt;BR /&gt;&lt;BR /&gt;This can be taken in multiple different directions - &lt;A href="about:blank" target="_self"&gt;alert tunings,&amp;nbsp;&lt;/A&gt;&lt;A href="http://&amp;lt;iframe%20width=&amp;quot;600&amp;quot; height=&amp;quot;338&amp;quot; src=&amp;quot;https://www.youtube.com/embed/4MAtHYsbl6s&amp;quot; title=&amp;quot;SOC Analysts - Understanding Incident Resources&amp;quot; frameborder=&amp;quot;0&amp;quot; allow=&amp;quot;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share&amp;quot; allowfullscreen&amp;gt;&amp;lt;/iframe&amp;gt;" target="_self"&gt;incident sources&lt;/A&gt;,&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics-Concepts" target="_self"&gt;analytics detection time intervals.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 14:42:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-best-practices/m-p/537113#M3996</guid>
      <dc:creator>mavraham</dc:creator>
      <dc:date>2023-03-30T14:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Incident Best Practices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-best-practices/m-p/537197#M4003</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167148"&gt;@mavraham&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;Thank you very much for your reply.&lt;BR /&gt;Indeed, maybe this is even nearly impossible or would take a very long time to document. I want to create a guideline, or maybe even an incident response plan, not only for myself but also for my colleagues just to be sure I am doing the right thing in case of an incident.&lt;BR /&gt;I know such things should rely on experience, but at the moment, I lack of that.&lt;BR /&gt;&lt;BR /&gt;I want to learn, know what to do, gain experience,... I will definitely check out the links you included, thank you for that.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 06:32:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-best-practices/m-p/537197#M4003</guid>
      <dc:creator>Jeroen_Proost</dc:creator>
      <dc:date>2023-03-31T06:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Incident Best Practices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-best-practices/m-p/537537#M4031</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/262810"&gt;@Jeroen_Proost&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check out our webinars (link below and with the help of SmartScore feature (link below), this will help/guide Analyst which incident to prioritize and investigate.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can explore our journey phases in our &lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr/ct-p/Cortex_XDR" target="_self"&gt;Live Community&lt;/A&gt; page and select whether you have Prevent or Pro license.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-webinars/customer-success-webinar-cortex-xdr-soc-analysts-understanding/ta-p/488372" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-webinars/customer-success-webinar-cortex-xdr-soc-analysts-understanding/ta-p/488372&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-webinars/cortex-xdr-customer-success-webinar-alert-tuning-operations/ta-p/505838" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-webinars/cortex-xdr-customer-success-webinar-alert-tuning-operations/ta-p/505838&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/cortex-xdr-how-to-video-smartscore/ta-p/513374" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/cortex-xdr-how-to-video-smartscore/ta-p/513374&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 06:06:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-best-practices/m-p/537537#M4031</guid>
      <dc:creator>jcandelaria</dc:creator>
      <dc:date>2023-04-04T06:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Incident Best Practices</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-best-practices/m-p/538218#M4075</link>
      <description>&lt;P&gt;Thank you very much&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/174003"&gt;@jcandelaria&lt;/a&gt;&amp;nbsp; !&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 09:12:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-best-practices/m-p/538218#M4075</guid>
      <dc:creator>Jeroen_Proost</dc:creator>
      <dc:date>2023-04-11T09:12:20Z</dc:date>
    </item>
  </channel>
</rss>

