<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Android Cortex XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/android-cortex-xdr/m-p/1245222#M8979</link>
    <description>&lt;P&gt;I want to know how to perform an XQL query for Android devices, where I search by hash and it shows me all the devices that have that .apk with that hash, or I can search by name.&lt;/P&gt;</description>
    <pubDate>Thu, 08 Jan 2026 14:59:24 GMT</pubDate>
    <dc:creator>QuestionAb</dc:creator>
    <dc:date>2026-01-08T14:59:24Z</dc:date>
    <item>
      <title>Android Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/android-cortex-xdr/m-p/1245222#M8979</link>
      <description>&lt;P&gt;I want to know how to perform an XQL query for Android devices, where I search by hash and it shows me all the devices that have that .apk with that hash, or I can search by name.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2026 14:59:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/android-cortex-xdr/m-p/1245222#M8979</guid>
      <dc:creator>QuestionAb</dc:creator>
      <dc:date>2026-01-08T14:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: Android Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/android-cortex-xdr/m-p/1246135#M9026</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/804344437"&gt;@QuestionAb&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To perform an XQL query for Android devices to find a specific&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;.apk&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;by its hash or name, you can use several approaches depending on whether you are looking for historical activity (logs) or the current installation status (inventory).&lt;/P&gt;
&lt;H4&gt;1. Searching by File Hash (SHA256)&lt;/H4&gt;
&lt;P&gt;To identify all devices where a specific file hash has been seen in historical activity, use the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;xdr_data&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;dataset. This search relies on the telemetry reported when the Android agent scans apps or when activities like installations occur.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;XQL Query Template (Historical Activity):&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="codehilite"&gt;
&lt;PRE&gt;&lt;CODE&gt;&lt;SPAN class="n"&gt;dataset&lt;/SPAN&gt; &lt;SPAN class="o"&gt;=&lt;/SPAN&gt; &lt;SPAN class="n"&gt;xdr_data&lt;/SPAN&gt;
&lt;SPAN class="o"&gt;|&lt;/SPAN&gt; &lt;SPAN class="n"&gt;filter&lt;/SPAN&gt; &lt;SPAN class="n"&gt;os_type&lt;/SPAN&gt; &lt;SPAN class="o"&gt;=&lt;/SPAN&gt; &lt;SPAN class="n"&gt;ENUM&lt;/SPAN&gt;&lt;SPAN class="p"&gt;.&lt;/SPAN&gt;&lt;SPAN class="n"&gt;OS_ANDROID&lt;/SPAN&gt;
&lt;SPAN class="o"&gt;|&lt;/SPAN&gt; &lt;SPAN class="n"&gt;filter&lt;/SPAN&gt; &lt;SPAN class="n"&gt;action_file_sha256&lt;/SPAN&gt; &lt;SPAN class="o"&gt;=&lt;/SPAN&gt; &lt;SPAN class="ss"&gt;"INSERT_HASH_HERE"&lt;/SPAN&gt;
&lt;SPAN class="o"&gt;|&lt;/SPAN&gt; &lt;SPAN class="n"&gt;fields&lt;/SPAN&gt; &lt;SPAN class="n"&gt;_time&lt;/SPAN&gt;&lt;SPAN class="p"&gt;,&lt;/SPAN&gt; &lt;SPAN class="n"&gt;agent_hostname&lt;/SPAN&gt;&lt;SPAN class="p"&gt;,&lt;/SPAN&gt; &lt;SPAN class="n"&gt;action_file_name&lt;/SPAN&gt;&lt;SPAN class="p"&gt;,&lt;/SPAN&gt; &lt;SPAN class="n"&gt;action_file_sha256&lt;/SPAN&gt;&lt;SPAN class="p"&gt;,&lt;/SPAN&gt; &lt;SPAN class="n"&gt;action_file_path&lt;/SPAN&gt;
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;EM&gt;Note: Ensure the hash is in SHA256 format, as this is the standard used for file identification in Cortex XDR.&lt;/EM&gt;&lt;/P&gt;
&lt;H4&gt;2. Searching by File Name&lt;/H4&gt;
&lt;P&gt;If you do not have the hash, you can search for the filename. For historical logs, use the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;action_file_name&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;XQL Query Template (Historical Activity):&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="codehilite"&gt;
&lt;PRE&gt;&lt;CODE&gt;&lt;SPAN class="n"&gt;dataset&lt;/SPAN&gt; &lt;SPAN class="o"&gt;=&lt;/SPAN&gt; &lt;SPAN class="n"&gt;xdr_data&lt;/SPAN&gt;
&lt;SPAN class="o"&gt;|&lt;/SPAN&gt; &lt;SPAN class="n"&gt;filter&lt;/SPAN&gt; &lt;SPAN class="n"&gt;os_type&lt;/SPAN&gt; &lt;SPAN class="o"&gt;=&lt;/SPAN&gt; &lt;SPAN class="n"&gt;ENUM&lt;/SPAN&gt;&lt;SPAN class="p"&gt;.&lt;/SPAN&gt;&lt;SPAN class="n"&gt;OS_ANDROID&lt;/SPAN&gt;
&lt;SPAN class="o"&gt;|&lt;/SPAN&gt; &lt;SPAN class="n"&gt;filter&lt;/SPAN&gt; &lt;SPAN class="n"&gt;action_file_name&lt;/SPAN&gt; &lt;SPAN class="k"&gt;contains&lt;/SPAN&gt; &lt;SPAN class="ss"&gt;"app_name"&lt;/SPAN&gt; 
&lt;SPAN class="o"&gt;|&lt;/SPAN&gt; &lt;SPAN class="n"&gt;fields&lt;/SPAN&gt; &lt;SPAN class="n"&gt;_time&lt;/SPAN&gt;&lt;SPAN class="p"&gt;,&lt;/SPAN&gt; &lt;SPAN class="n"&gt;agent_hostname&lt;/SPAN&gt;&lt;SPAN class="p"&gt;,&lt;/SPAN&gt; &lt;SPAN class="n"&gt;action_file_name&lt;/SPAN&gt;&lt;SPAN class="p"&gt;,&lt;/SPAN&gt; &lt;SPAN class="n"&gt;action_file_sha256&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Happy New Year!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 15:23:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/android-cortex-xdr/m-p/1246135#M9026</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-01-21T15:23:01Z</dc:date>
    </item>
  </channel>
</rss>

