<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OS Fingerprinting feature in Distributed Network Scan (Pro version) in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/os-fingerprinting-feature-in-distributed-network-scan-pro/m-p/572869#M5875</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1637048063"&gt;@PhyoWaiSoe&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This statement means that at least two neighbour endpoints should be present within a subnet for agent to perform ping or NMAP scan. In other words, if there is only one endpoint present within a subnet then no other endpoint is available for it to do the scan.&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jan 2024 14:27:56 GMT</pubDate>
    <dc:creator>nsinghvirk</dc:creator>
    <dc:date>2024-01-12T14:27:56Z</dc:date>
    <item>
      <title>OS Fingerprinting feature in Distributed Network Scan (Pro version)</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/os-fingerprinting-feature-in-distributed-network-scan-pro/m-p/571133#M5813</link>
      <description>&lt;P&gt;Hi All,&lt;BR /&gt;We are using XDR Pro version with agent version 8.2. I am curious about this &lt;STRONG&gt;OS fingerprinting&lt;/STRONG&gt; feature under Distributed Network scan setting in Agent profile. I have already configured Network Location Configuration and also configured other things as shown in the attached screenshot. I was hoping it would return the OS type/version of other systems the XDR agents discovered. But so far, it doesn't seem to be doing much. Am I missing something?&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Distributed Network Scan" style="width: 734px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56147iFD7576299FC40149/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="XDR Screenshot.png" alt="Distributed Network Scan" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Distributed Network Scan&lt;/span&gt;&lt;/span&gt;&lt;BR /&gt;My network location configuration is set like this (actual DNS server name/IP address changed for the screenshot).&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Network location" style="width: 796px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56148i4C4261BBFCDDB5D9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="network loc config.png" alt="Network location" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Network location&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2023 15:39:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/os-fingerprinting-feature-in-distributed-network-scan-pro/m-p/571133#M5813</guid>
      <dc:creator>PhyoWaiSoe</dc:creator>
      <dc:date>2023-12-28T15:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: OS Fingerprinting feature in Distributed Network Scan (Pro version)</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/os-fingerprinting-feature-in-distributed-network-scan-pro/m-p/572070#M5852</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1637048063"&gt;@PhyoWaiSoe&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;Apologies for late response. Information provided via screenshot looks correct. Below are the few key factors in network configuration that can affect scanning.&lt;/P&gt;
&lt;UL class="p-rich_text_list p-rich_text_list__bullet" data-stringify-type="unordered-list" data-indent="1" data-border="0"&gt;
&lt;LI data-stringify-indent="1" data-stringify-border="0"&gt;Subnet mask settings and name service configuration influence the scanning&lt;/LI&gt;
&lt;LI data-stringify-indent="1" data-stringify-border="0"&gt;Network Location configuration should be enabled&lt;/LI&gt;
&lt;LI data-stringify-indent="1" data-stringify-border="0"&gt;Excluded IP address ranges will not be scanned&lt;/LI&gt;
&lt;LI data-stringify-indent="1" data-stringify-border="0"&gt;At least 2 peers are required to be detected for the agent to be assigned the scanning task.&lt;/LI&gt;
&lt;LI data-stringify-indent="1" data-stringify-border="0"&gt;This scan occurs at subnet level and it will not go over L3 boundary.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Below are the expected results from ping and NMAP scans.&lt;/P&gt;
&lt;UL class="p-rich_text_list p-rich_text_list__bullet" data-stringify-type="unordered-list" data-indent="1" data-border="0"&gt;
&lt;LI data-stringify-indent="1" data-stringify-border="0"&gt;Ping:&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL class="p-rich_text_list p-rich_text_list__bullet" data-stringify-type="unordered-list" data-indent="2" data-border="0"&gt;
&lt;LI data-stringify-indent="2" data-stringify-border="0"&gt;IP address&lt;/LI&gt;
&lt;LI data-stringify-indent="2" data-stringify-border="0"&gt;Mac address&lt;/LI&gt;
&lt;LI data-stringify-indent="2" data-stringify-border="0"&gt;Hostname&lt;/LI&gt;
&lt;LI data-stringify-indent="2" data-stringify-border="0"&gt;Platform (Windows/Mac/Linux)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL class="p-rich_text_list p-rich_text_list__bullet" data-stringify-type="unordered-list" data-indent="2" data-border="0"&gt;
&lt;LI data-stringify-indent="2" data-stringify-border="0"&gt;NMap&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL class="p-rich_text_list p-rich_text_list__bullet" data-stringify-type="unordered-list" data-indent="2" data-border="0"&gt;
&lt;LI data-stringify-indent="2" data-stringify-border="0"&gt;IP address&lt;/LI&gt;
&lt;LI data-stringify-indent="2" data-stringify-border="0"&gt;Hostname&lt;/LI&gt;
&lt;LI data-stringify-indent="2" data-stringify-border="0"&gt;Platform&lt;/LI&gt;
&lt;LI data-stringify-indent="2" data-stringify-border="0"&gt;OS Version&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If everything is configured as per the rules mentioned above than please raise a TAC case. This may require additional analysis.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please c&lt;SPAN&gt;lick&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;to acknowledge that the answer to your question has been provided.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 12:48:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/os-fingerprinting-feature-in-distributed-network-scan-pro/m-p/572070#M5852</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2024-01-08T12:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: OS Fingerprinting feature in Distributed Network Scan (Pro version)</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/os-fingerprinting-feature-in-distributed-network-scan-pro/m-p/572811#M5870</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/256101"&gt;@nsinghvirk&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;Thanks for the comprehensive reply. Because I am a total beginner when it comes to Cortex XDR, I am not clear about this sentence. Can you please explain a bit more? Thanks once again.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;UL class="p-rich_text_list p-rich_text_list__bullet" data-stringify-type="unordered-list" data-indent="1" data-border="0"&gt;
&lt;LI data-stringify-indent="1" data-stringify-border="0"&gt;At least 2 peers are required to be detected for the agent to be assigned the scanning task.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 12 Jan 2024 03:35:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/os-fingerprinting-feature-in-distributed-network-scan-pro/m-p/572811#M5870</guid>
      <dc:creator>PhyoWaiSoe</dc:creator>
      <dc:date>2024-01-12T03:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: OS Fingerprinting feature in Distributed Network Scan (Pro version)</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/os-fingerprinting-feature-in-distributed-network-scan-pro/m-p/572869#M5875</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1637048063"&gt;@PhyoWaiSoe&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This statement means that at least two neighbour endpoints should be present within a subnet for agent to perform ping or NMAP scan. In other words, if there is only one endpoint present within a subnet then no other endpoint is available for it to do the scan.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 14:27:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/os-fingerprinting-feature-in-distributed-network-scan-pro/m-p/572869#M5875</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2024-01-12T14:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: OS Fingerprinting feature in Distributed Network Scan (Pro version)</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/os-fingerprinting-feature-in-distributed-network-scan-pro/m-p/596727#M7141</link>
      <description>&lt;P&gt;Hello, could you clarify where you dump the information you get from the scan, and what information do you dump? Hostname, OS, IP, agent installed?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2024 08:35:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/os-fingerprinting-feature-in-distributed-network-scan-pro/m-p/596727#M7141</guid>
      <dc:creator>JPrezHidalgo</dc:creator>
      <dc:date>2024-09-04T08:35:58Z</dc:date>
    </item>
  </channel>
</rss>

