<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to keep cortex xdr in passive mode in Endpoint (Traps) Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/how-to-keep-cortex-xdr-in-passive-mode/m-p/588865#M1151</link>
    <description>&lt;P&gt;that should depend on what you mean by migration to CrowdStrike. EPP or EDR?&lt;/P&gt;
&lt;P&gt;Crowdstrike is cloud native EDR. The EPP is afterthought. Be more specific&lt;/P&gt;
&lt;P&gt;If you aren't going all in with the Cortex Pro (EDR/XDR), don't give up the Cortex "Prevent" (EPP) on the host. One informs the other.&amp;nbsp; As long as its there you can always switch back. flipping the script so to speak and 2 sources of intel is better than 1. As former McAfee ATA Ive built the technology platforms in a few flavors but I personally like the Cortex Prevent EPP and Defender EDR (Passive). I like it for what it is.. Metrics for the crew and telemetry for troubleshooting. If i had a crew of analyst or at least one good one and some money id go all in on the Palo XDR platform. Shiny toys get dull if you cant or dont use them&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jun 2024 18:45:49 GMT</pubDate>
    <dc:creator>JohnSmith7732</dc:creator>
    <dc:date>2024-06-05T18:45:49Z</dc:date>
    <item>
      <title>How to keep cortex xdr in passive mode</title>
      <link>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/how-to-keep-cortex-xdr-in-passive-mode/m-p/588461#M1149</link>
      <description>&lt;P&gt;Hello All,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are initiating the migration process from cortex xdr to crowdstrike, so can we put the cortex xdr in passive mode.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sakshi Seth&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 07:26:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/how-to-keep-cortex-xdr-in-passive-mode/m-p/588461#M1149</guid>
      <dc:creator>Seth_Sakshi</dc:creator>
      <dc:date>2024-05-31T07:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to keep cortex xdr in passive mode</title>
      <link>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/how-to-keep-cortex-xdr-in-passive-mode/m-p/588865#M1151</link>
      <description>&lt;P&gt;that should depend on what you mean by migration to CrowdStrike. EPP or EDR?&lt;/P&gt;
&lt;P&gt;Crowdstrike is cloud native EDR. The EPP is afterthought. Be more specific&lt;/P&gt;
&lt;P&gt;If you aren't going all in with the Cortex Pro (EDR/XDR), don't give up the Cortex "Prevent" (EPP) on the host. One informs the other.&amp;nbsp; As long as its there you can always switch back. flipping the script so to speak and 2 sources of intel is better than 1. As former McAfee ATA Ive built the technology platforms in a few flavors but I personally like the Cortex Prevent EPP and Defender EDR (Passive). I like it for what it is.. Metrics for the crew and telemetry for troubleshooting. If i had a crew of analyst or at least one good one and some money id go all in on the Palo XDR platform. Shiny toys get dull if you cant or dont use them&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 18:45:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/endpoint-traps-discussions/how-to-keep-cortex-xdr-in-passive-mode/m-p/588865#M1151</guid>
      <dc:creator>JohnSmith7732</dc:creator>
      <dc:date>2024-06-05T18:45:49Z</dc:date>
    </item>
  </channel>
</rss>

