Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4556 Views
  • 0 replies
  • 3 Likes

Resolved! Monitoring new network interface connections (USB NICs) via BIOC / XQL — Looking for best practices

Hi everyone,I am looking for guidance or community insights on how to monitor and track the connection and usage of networkndevices (especially USB Ethernet adapters, Wi-Fi dongles, and USB tethering) on Windows endpoints. Our goal is to detect whenever a new network interface is attached/enabled, capture its timestamp, and ideally trigger an al...

Whitelisting AI?

Hi, is there a way for XDR to create an AI whitelist so that only access to permitted AI executables is allowed and everything else automatically blocked?

Resolved! Non-Persistent VDI – File Collection and Investigation with XDR

Hi everyone, I need some help/advice. I’ve been seeing some cases on non-persistent VDIs where we receive alerts such as “Script Engine Activity - 3121803131”. Basically, the Cortex XDR alert is related to an HTML file hosted on a ShareFile share that I don’t have access to. From what I understand, the HTML file is essentially a web-page templat...

tlmarques by L4 Transporter
  • 144 Views
  • 1 replies
  • 0 Likes

XDR CPU Spikes and logging levels

Hi Has anyone else come across this? I keep seeing CPU spikes on production web servers running v9.3 and 9.3 that has an impact on the end users. They come in roughly 45 minute bursts and running procmon indicates the cyserver.exe is causing them. One suggestion ive had is to clear the content cache in the possibility that a bad update is tryi...

XDR agent reboot recover everytime

Hi guys, Recently, we identified several computers running Cortex XDR version 9.2.0.120 with Content Version 2340-38788. After the machines start, connect to the tenant, and receive the latest content/information, they start rebooting approximately every minute. The Windows message displayed is: “You’re about to be signed out”“Reinício agendado...

tlmarques by L4 Transporter
  • 194 Views
  • 1 replies
  • 0 Likes

Cortex XDR 8.9 Non-Persistent Citrix Servers and Cache Write Issue

Hello everyone, We have encountered and issue where the target servers do not get content updates. The citrix Windows servers reboot nightly with the golden image configurations but do not receive the latest content updates. At the same time, around noon we have to reboot the target servers due to write cache filling up to 100%. Have you enco...

Cortex XDR: Excluding Specific AI Agent PowerShell Activity While Maintaining Blocking

Currently, PowerShell activity generated by an AI Agent is being detected by Cortex XDR. After investigation, we confirmed that this activity is a false positive, as the AI Agent uses PowerShell for administrative/management purposes. Due to our internal operational policy, we cannot use Legacy Exceptions, so we are considering using Exclusion R...

.522643 by L1 Bithead
  • 136 Views
  • 1 replies
  • 0 Likes

Resolved! Create an issue when FIM events detected

Hello experts, We plan to get the FIM module on top of my XDR. Having set up with FIM Profile and Policy, we could be able to see those events successfully. with the following information: 2. Dataset and Presets for FIM Dataset: xdr_data XQL Filter:dataset = xdr_data | filter fim_event = true Console: Inventory → Endpoints → File Integrity...

XDR Alert Dump – Finding the File That Triggered the Alert

I have a question. When we perform a Dump Alert and get the ZIP file, how can we analyze it in more detail? For example, if I want to see the .ps1 file that a particular user executed on the machine and that triggered the alert, would that file be included in the dump? I’ve already searched everywhere, but I can’t find it. I can see a folder cal...

tlmarques by L4 Transporter
  • 128 Views
  • 1 replies
  • 0 Likes

Resolved! Low Incident

We have integrated Cortex XDR with Elastic SIEM. Our SOC process currently creates a ticket for every Cortex XDR incident/case, including Low, Medium, and High severity incidents. Is Palo Alto's recommended best practice to create tickets for all Low severity incidents, or should Low severity alerts/incidents be monitored and correlated before t...

R.Abdeen by L0 Member
  • 267 Views
  • 1 replies
  • 0 Likes

XDR 4 - Integrations AD Query

Hi everyone, on Cortex XDR 4 ,we can build small playbooks, and one of the available actions is AD Query.My question is: what is required to configure this integration? I see that the integration asks for the IP address, domain user, and other parameters, but if the Active Directory is on-premises, how does Cortex XDR establish the connection?Wh...

tlmarques by L4 Transporter
  • 2013 Views
  • 4 replies
  • 0 Likes

Cortex XDR JDP method instrumentation causing severe Java runtime slowness (agent 9.2.0.120) — follow-up to solved cyjagent crash thread

This is a follow-up to a previously solved thread: Cortex XDR cyjagent.dll injection causes JVM startup crash, where @susekar confirmed the known JDP/JVM conflict (CPATR-38467 / CPATR-18158). Thanks for that confirmation. Since the solution there is already accepted, raising this as a separate topic: we've now observed a second symptom from the ...

Predicting blocked alerts when switching Malware/Exploit modules from "Report" to "Block"

Hi everyone, We are currently in the process of fine-tuning our Cortex XDR tenant. At the moment, we have several modules within our Malware and Exploit security profiles set to "Report" mode. We are planning to harden our security posture and switch these modules to "Block" mode. However, before making this change, we want to assess the potenti...

Cortex XDR – Automatically Resolve Alerts/Issues as "Known Issue" Using Playbook or Predefined Command

Hello Team, We are using a Cortex XDR tenant and would like to know whether there is a supported way to automatically update an alert/issue resolution to "Known Issue" using a predefined command, automation, or playbook action. Our goal is to avoid manual analyst intervention for alerts that have already been validated as known benign activity a...

  • 2658 Posts
  • 102 Subscriptions
Top Solution Authors
Top Liked Authors