Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 4052 Views
  • 0 replies
  • 3 Likes

Create a IOC without incident

Good morning,

Today I would like to create a block for two malicious files that I found in our environment. I noticed that I can create an IOC to block paths, file names, IPs, etc. I have already created an IOC using a wildcard for the file name: PDF

...

Resolved! XDR add more values to incident classification

 

Hi everyone,

When I close each incident, I need to add the CSIRT taxonomy flags (from the ENISA Reference Incident Classification Taxonomy: https://www.enisa.europa.eu/publications/reference-incident-classification-taxonomy) to the Cortex XDR case.

...

tlmarques by L4 Transporter
  • 444 Views
  • 4 replies
  • 0 Likes

Reconnect after endpoint cleanup

Hello,

 

I'm thinking about using the Endpoint Administration Cleanup tool.

However, I wanted to be sure if an endpoint is mistakenly deleted would shows up again in our tenant (if connected in the next 90 days).

Did anyone has experienced it yet?

 

...

Cortex XDR Pro / Browser extensions

Has anyone ever configured their environment to detect on unauthorized or unsupported browser extensions? Or conduct a threat hunt based on known facts?

 

We've seen some slip through the cracks and I know Cortex doesn't natively detect abused or mal

...

Inquiry regarding Tenant Backu & Recovery

I am looking for detailed information regarding the backup and recovery lifecycle for a Cortex XDR tenant. Specifically, I have the following questions:

  1. Automated Backups: Does Palo Alto Networks perform regular backups of tenant-specific configurat

...

R.Abdeen by L0 Member
  • 136 Views
  • 1 replies
  • 0 Likes

Cortex Management Report

I want to know if I can generate a report of Cortex's actions over the last year or 3 months, such as what he blocked, quarantined, isolated, etc., but in a graph format. I tried using a widget library, but I can't find a way to represent that action

...

XDR 5.0 - opinion

Cortex Cortex XDR 5.0 tenant. What's your opinion

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-5.x-Release-Notes/Release-Information

 

 

tlmarques_0-1770656806817.png
tlmarques by L4 Transporter
  • 367 Views
  • 8 replies
  • 0 Likes

Resolved! Sending USB Alerts via syslog (Cortex XDR)

Hello,

We have received a request asking whether it is possible for administrators to receive alert emails whenever a USB device is connected to any endpoints.
(*Currently, the USB policy in Exploit – Device Configuration is set to Read Only.)

(* I th

...

YSONG464633_0-1770612974843.png

Resolved! Cortex XDR Tenant Auto-Upgrade 3.17 → 5.0: UI mixed theme, AI pages stuck loading, Marketplace/Playbook Catalog empty + ingestion quota warning

I tried to open a Support case, but none of the available issue categories allowed me to create a case and I was redirected to Live Community for assistance. I’m posting here to get guidance on the likely root cause and recommended next steps.

 

Afte

...

  • 2539 Posts
  • 94 Subscriptions
Top Liked Authors