<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Cortex XDR - Customer Success Webinar: Endpoint Administration - Part 1 in Cortex XDR Videos</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-videos/cortex-xdr-customer-success-webinar-endpoint-administration-part/ta-p/513051</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;Endpoint Administration Webinar Part 1&lt;/P&gt;
&lt;P&gt;This webinar covers the&amp;nbsp;&lt;SPAN&gt;Cortex XDR agent-related administrative tasks from installations, architecture, common issues, and our pro tips!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Watch the video and use the resources that were shared during the webinar, listed below:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;div class="video-embed-center video-embed"&gt;&lt;iframe class="embedly-embed" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2F4HsvsVDTE3Y%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D4HsvsVDTE3Y&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2F4HsvsVDTE3Y%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" width="400" height="225" scrolling="no" title="Cortex XDR Customer Success Webinar: Endpoint Administration" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture;" allowfullscreen="true"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;U&gt;Resources&lt;/U&gt;:&lt;/H4&gt;
&lt;H5&gt;&lt;SPAN&gt;Adding proxy list during the installation:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;EM&gt;msiexec /i c:\install\cortexxdr.msi proxy_list=”My.Network.Name:808,10.196.20.244:8080”&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For endpoint side-local uninstall - Disable Tamper Protect first&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;cytool protect disable&lt;/EM&gt;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;&lt;BR /&gt;XQL custom widget for count of endpoints by minor release:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;EM&gt;config case_sensitive = false timeframe=30d&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;|dataset = endpoints&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| filter endpoint_status = ENUM.CONNECTED or endpoint_status = ENUM.DISCONNECTED&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| alter agent_version_formatted = regextract(agent_version ,"^\D*(\d+(?:\.\d+)?)")&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| arrayexpand agent_version_formatted&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| comp count (agent_version_formatted ) as no_of_agents by agent_version_formatted&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| fields agent_version_formatted , no_of_agents&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| sort asc agent_version_formatted&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| view graph type = column subtype = grouped,horizontal header = "Count of Endpoints by Minor Release" show_callouts = `true` xaxis = agent_version_formatted yaxis = no_of_agents legend = `false` xaxistitle = "Agents by Minor Release"&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;H5&gt;&lt;BR /&gt;&lt;SPAN&gt;List of duplicate endpoints:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;EM&gt;dataset = endpoints&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| fields endpoint_id, endpoint_name, last_seen&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| comp count() as count by endpoint_name addrawdata = true as raw_data&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| filter count &amp;gt; 1&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| sort desc count&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| alter endpoint_name = arrayindex (raw_data, 0) -&amp;gt; endpoint_name&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| alter endpoint_id = arrayindex (raw_data, 0) -&amp;gt; endpoint_id&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| alter last_seen = arrayindex (raw_data, 0) -&amp;gt; last_seen&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;XQL custom widget for top 20 duplicate endpoints:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;EM&gt;dataset = endpoints&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| fields endpoint_id, endpoint_name, last_seen&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| comp count() as no_of_duplicates by endpoint_name&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| filter no_of_duplicates &amp;gt; 1&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| fields endpoint_name, no_of_duplicates&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| sort desc no_of_duplicates&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| view graph type = column subtype = grouped,horizontal header = "Top 20 duplicate endpoints" show_callouts = `true` xaxis = endpoint_name yaxis = no_of_duplicates legend = `false` xaxistitle = "Number of duplicates per endpoint"&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;Count of endpoints per operational status:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;EM&gt;dataset = endpoints&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| fields endpoint_name, is_edr_enabled&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| comp count_distinct(endpoint_name) as counter by is_edr_enabled&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| view graph type = pie show_callouts = `true` xaxis = is_edr_enabled yaxis = counter&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;Live Terminal command samples with Shift + Enter to execute:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;EM&gt;hostname&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;C:\"Program Files"\"Palo Alto Networks"\Traps\cytool info&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;Live Terminal Python script&amp;nbsp; samples with Shift + Enter to execute:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;EM&gt;import os&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;print(os.listdir('c:\\users'))&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;Demo Cytool commands (Tool used: Process Explorer)&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN&gt;The list below is not an exhaustive list of = Attached Slide 24 and use the cytool helper to see all the available cytool commands&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;===========================&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;On Windows - &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-8/cortex-xdr-agent-admin/cortex-xdr-agent-for-windows/troubleshoot-cortex-xdr-for-windows/cytool" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-8/cortex-xdr-agent-admin/cortex-xdr-agent-for-windows/troubleshoot-cortex-xdr-for-windows/cytool&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;===========================&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Run CMD as administrator&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Change directory to Cortex XDR binary folder - un command 'cd "C:\Program Files\Palo Alto Networks\Traps" '&lt;/LI&gt;
&lt;LI&gt;Enter the Supervisor Password (Uninstall Password) for privileged commands:&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;cytool runtime query&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;cytool protect query&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;cytool websocket query&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;cytool connectivity_test&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Another variant without&amp;nbsp;changing path:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;C:\"Program Files"\"Palo Alto Networks"\Traps\cytool info&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;An alternative way to pause protection:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;cytool security [enable | disable]&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;enable &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Enables security profiles.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;disable&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Disables security profiles.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;ID extraction &amp;amp; reconnection &lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN&gt;To extract the distribution ID locally and reconnect back the agent (new distribution_id can be copied from your Cortex XDR tenant as well)&lt;BR /&gt;&lt;/SPAN&gt;cat /opt/traps/config/trapsd.xml | grep -i distribution_id&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;Cytool reconnect&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;cytool reconnect force DISTRIBUTION_ID&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Try without distribution ID first;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Note: cytool reconnect force command will create duplicates and a new instance. As a result, its not meant to be used multiple times&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;===========================&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;On macOS&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;===========================&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sudo /Library/Application\ Support/PaloAltoNetworks/Traps/bin/cytool runtime query&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sudo /Library/Application\ Support/PaloAltoNetworks/Traps/bin/cytool runtime stop all&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sudo /Library/Application\ Support/PaloAltoNetworks/Traps/bin/cytool runtime start all&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sudo /Library/Application\ Support/PaloAltoNetworks/Traps/bin/cytool checkin&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;============================&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Linux&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;============================&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Processes&amp;nbsp;Protected by Cortex XDR:&amp;nbsp;&lt;/SPAN&gt;./cytool enum&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Websocket:&amp;nbsp;&lt;/SPAN&gt;./cytool websocket query&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Checkin:&amp;nbsp;&lt;/SPAN&gt;./cytool Checkin&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Last Time Checkin:&amp;nbsp;&lt;/SPAN&gt;./cytool last_checkin&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Agent files and directories in use for logs, EDR, download, etc:&amp;nbsp;&lt;/SPAN&gt;cat /opt/traps/config/common.xml&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Connectivity:&amp;nbsp;&lt;/SPAN&gt;./cytool connectivity_test&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Agent version:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;cat /opt/traps/version.txt&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Agent Distribution ID:&lt;BR /&gt;cat /opt/traps/config/trapsd.xml | grep -i distribution_id&lt;BR /&gt;cat /opt/traps/config/db_backup/distribution_id.txt&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Proxy IP address Configured:&amp;nbsp;&lt;/SPAN&gt;cat /opt/traps/config/trapsd.xml | grep -i proxy_list&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;=========================&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;Agent functionality: &lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN&gt;In order to implement the agent functionality, the agent includes the ff components&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Drivers&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Services&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;Cytool runtime query:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN&gt;Processes: t&lt;/SPAN&gt;he processes that start running when the service starts or when needed:&lt;BR /&gt;&lt;EM&gt;cyserver.exe&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;cortex-xdr-payload.exe&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;tlaworker.exe&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;cytray.exe&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;cyveraconsole.exe&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;DLL:&lt;/H5&gt;
&lt;P&gt;&lt;EM&gt;cyinjct.dll&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;cyvrtrap.dll&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;cyvera.dll&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;Registry:&amp;nbsp;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;Holds important keys of policy information, policy configurations, protected processes&lt;BR /&gt;&lt;EM&gt;Computer\HKEY_LOCAL_MACHINE\SYSTEM\Cyvera\policy&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 17 Oct 2022 17:46:23 GMT</pubDate>
    <dc:creator>rtsedaka</dc:creator>
    <dc:date>2022-10-17T17:46:23Z</dc:date>
    <item>
      <title>Cortex XDR - Customer Success Webinar: Endpoint Administration - Part 1</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-videos/cortex-xdr-customer-success-webinar-endpoint-administration-part/ta-p/513051</link>
      <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;Endpoint Administration Webinar Part 1&lt;/P&gt;
&lt;P&gt;This webinar covers the&amp;nbsp;&lt;SPAN&gt;Cortex XDR agent-related administrative tasks from installations, architecture, common issues, and our pro tips!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Watch the video and use the resources that were shared during the webinar, listed below:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;div class="video-embed-center video-embed"&gt;&lt;iframe class="embedly-embed" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2F4HsvsVDTE3Y%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D4HsvsVDTE3Y&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2F4HsvsVDTE3Y%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" width="400" height="225" scrolling="no" title="Cortex XDR Customer Success Webinar: Endpoint Administration" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture;" allowfullscreen="true"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;U&gt;Resources&lt;/U&gt;:&lt;/H4&gt;
&lt;H5&gt;&lt;SPAN&gt;Adding proxy list during the installation:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;EM&gt;msiexec /i c:\install\cortexxdr.msi proxy_list=”My.Network.Name:808,10.196.20.244:8080”&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For endpoint side-local uninstall - Disable Tamper Protect first&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;cytool protect disable&lt;/EM&gt;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;&lt;BR /&gt;XQL custom widget for count of endpoints by minor release:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;EM&gt;config case_sensitive = false timeframe=30d&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;|dataset = endpoints&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| filter endpoint_status = ENUM.CONNECTED or endpoint_status = ENUM.DISCONNECTED&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| alter agent_version_formatted = regextract(agent_version ,"^\D*(\d+(?:\.\d+)?)")&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| arrayexpand agent_version_formatted&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| comp count (agent_version_formatted ) as no_of_agents by agent_version_formatted&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| fields agent_version_formatted , no_of_agents&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| sort asc agent_version_formatted&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| view graph type = column subtype = grouped,horizontal header = "Count of Endpoints by Minor Release" show_callouts = `true` xaxis = agent_version_formatted yaxis = no_of_agents legend = `false` xaxistitle = "Agents by Minor Release"&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;H5&gt;&lt;BR /&gt;&lt;SPAN&gt;List of duplicate endpoints:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;EM&gt;dataset = endpoints&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| fields endpoint_id, endpoint_name, last_seen&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| comp count() as count by endpoint_name addrawdata = true as raw_data&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| filter count &amp;gt; 1&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| sort desc count&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| alter endpoint_name = arrayindex (raw_data, 0) -&amp;gt; endpoint_name&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| alter endpoint_id = arrayindex (raw_data, 0) -&amp;gt; endpoint_id&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| alter last_seen = arrayindex (raw_data, 0) -&amp;gt; last_seen&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;XQL custom widget for top 20 duplicate endpoints:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;EM&gt;dataset = endpoints&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| fields endpoint_id, endpoint_name, last_seen&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| comp count() as no_of_duplicates by endpoint_name&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| filter no_of_duplicates &amp;gt; 1&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| fields endpoint_name, no_of_duplicates&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| sort desc no_of_duplicates&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| view graph type = column subtype = grouped,horizontal header = "Top 20 duplicate endpoints" show_callouts = `true` xaxis = endpoint_name yaxis = no_of_duplicates legend = `false` xaxistitle = "Number of duplicates per endpoint"&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;Count of endpoints per operational status:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;EM&gt;dataset = endpoints&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| fields endpoint_name, is_edr_enabled&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| comp count_distinct(endpoint_name) as counter by is_edr_enabled&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;| view graph type = pie show_callouts = `true` xaxis = is_edr_enabled yaxis = counter&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;Live Terminal command samples with Shift + Enter to execute:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;EM&gt;hostname&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;C:\"Program Files"\"Palo Alto Networks"\Traps\cytool info&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;Live Terminal Python script&amp;nbsp; samples with Shift + Enter to execute:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;EM&gt;import os&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;print(os.listdir('c:\\users'))&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;Demo Cytool commands (Tool used: Process Explorer)&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN&gt;The list below is not an exhaustive list of = Attached Slide 24 and use the cytool helper to see all the available cytool commands&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;===========================&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;On Windows - &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-8/cortex-xdr-agent-admin/cortex-xdr-agent-for-windows/troubleshoot-cortex-xdr-for-windows/cytool" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-8/cortex-xdr-agent-admin/cortex-xdr-agent-for-windows/troubleshoot-cortex-xdr-for-windows/cytool&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;===========================&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Run CMD as administrator&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Change directory to Cortex XDR binary folder - un command 'cd "C:\Program Files\Palo Alto Networks\Traps" '&lt;/LI&gt;
&lt;LI&gt;Enter the Supervisor Password (Uninstall Password) for privileged commands:&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;cytool runtime query&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;cytool protect query&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;cytool websocket query&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;cytool connectivity_test&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Another variant without&amp;nbsp;changing path:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;C:\"Program Files"\"Palo Alto Networks"\Traps\cytool info&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;An alternative way to pause protection:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;cytool security [enable | disable]&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;enable &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Enables security profiles.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;disable&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Disables security profiles.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;ID extraction &amp;amp; reconnection &lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN&gt;To extract the distribution ID locally and reconnect back the agent (new distribution_id can be copied from your Cortex XDR tenant as well)&lt;BR /&gt;&lt;/SPAN&gt;cat /opt/traps/config/trapsd.xml | grep -i distribution_id&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;Cytool reconnect&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;cytool reconnect force DISTRIBUTION_ID&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Try without distribution ID first;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Note: cytool reconnect force command will create duplicates and a new instance. As a result, its not meant to be used multiple times&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;===========================&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;On macOS&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;===========================&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sudo /Library/Application\ Support/PaloAltoNetworks/Traps/bin/cytool runtime query&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sudo /Library/Application\ Support/PaloAltoNetworks/Traps/bin/cytool runtime stop all&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sudo /Library/Application\ Support/PaloAltoNetworks/Traps/bin/cytool runtime start all&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sudo /Library/Application\ Support/PaloAltoNetworks/Traps/bin/cytool checkin&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;============================&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Linux&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;============================&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Processes&amp;nbsp;Protected by Cortex XDR:&amp;nbsp;&lt;/SPAN&gt;./cytool enum&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Websocket:&amp;nbsp;&lt;/SPAN&gt;./cytool websocket query&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Checkin:&amp;nbsp;&lt;/SPAN&gt;./cytool Checkin&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Last Time Checkin:&amp;nbsp;&lt;/SPAN&gt;./cytool last_checkin&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Agent files and directories in use for logs, EDR, download, etc:&amp;nbsp;&lt;/SPAN&gt;cat /opt/traps/config/common.xml&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Connectivity:&amp;nbsp;&lt;/SPAN&gt;./cytool connectivity_test&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Agent version:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;cat /opt/traps/version.txt&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Agent Distribution ID:&lt;BR /&gt;cat /opt/traps/config/trapsd.xml | grep -i distribution_id&lt;BR /&gt;cat /opt/traps/config/db_backup/distribution_id.txt&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Proxy IP address Configured:&amp;nbsp;&lt;/SPAN&gt;cat /opt/traps/config/trapsd.xml | grep -i proxy_list&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;=========================&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;Agent functionality: &lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN&gt;In order to implement the agent functionality, the agent includes the ff components&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Drivers&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Services&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;Cytool runtime query:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN&gt;Processes: t&lt;/SPAN&gt;he processes that start running when the service starts or when needed:&lt;BR /&gt;&lt;EM&gt;cyserver.exe&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;cortex-xdr-payload.exe&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;tlaworker.exe&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;cytray.exe&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;cyveraconsole.exe&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;DLL:&lt;/H5&gt;
&lt;P&gt;&lt;EM&gt;cyinjct.dll&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;cyvrtrap.dll&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;cyvera.dll&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN&gt;Registry:&amp;nbsp;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;Holds important keys of policy information, policy configurations, protected processes&lt;BR /&gt;&lt;EM&gt;Computer\HKEY_LOCAL_MACHINE\SYSTEM\Cyvera\policy&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 17 Oct 2022 17:46:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-videos/cortex-xdr-customer-success-webinar-endpoint-administration-part/ta-p/513051</guid>
      <dc:creator>rtsedaka</dc:creator>
      <dc:date>2022-10-17T17:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR - Customer Success Webinar: Endpoint Administration - Part 1</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-videos/cortex-xdr-customer-success-webinar-endpoint-administration-part/tac-p/533130#M49</link>
      <description>&lt;P&gt;Good job&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":folded_hands:"&gt;🙏&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2023 12:10:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-videos/cortex-xdr-customer-success-webinar-endpoint-administration-part/tac-p/533130#M49</guid>
      <dc:creator>Saliha</dc:creator>
      <dc:date>2023-03-03T12:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR - Customer Success Webinar: Endpoint Administration - Part 1</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-videos/cortex-xdr-customer-success-webinar-endpoint-administration-part/tac-p/592574#M50</link>
      <description>&lt;P&gt;sorry but very hard to follow. had to stop 17 minutes in as unsure what last 10 were about.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 17:57:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-videos/cortex-xdr-customer-success-webinar-endpoint-administration-part/tac-p/592574#M50</guid>
      <dc:creator>B.Candelora</dc:creator>
      <dc:date>2024-07-19T17:57:18Z</dc:date>
    </item>
  </channel>
</rss>

