Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 767 Views
  • 0 replies
  • 2 Likes

BTP Exception not working for ps1 script

Hi Team - 

I've created a Legacy Agent Exception Rule to prevent the Behavioral Threat Protection component from blocking a specific (and legitimate) .ps1 file on my network (within a specific user profile), but Cortex keeps blocking the script.

The

...

User Message on IOC trigger

Hi,

 

We have enabled user notifications in agent profile settings, when an event like malware detection occurs it is displayed to the user immediately. However, it does not show a notification for an IOC. Can we make a message appear for an IOC even

...

RedHat 8/9 XDR client count limited

As I have added clients to my XDR Linux group I have seen a situation where I hit a limit on client count (under 20 BTW). After I have them all added there will be 2 or 3 missing. If I restart the process on a missing client, that one immediately app

...

Cortex Broker Mapper scans

We’re experiencing an issue with Cortex brokers related to the network mapper.
When we run network scans using the "ICMP Echo" flag, the scan completes successfully and everything works as expected.

However, when performing a "TCP SYN" scan on the foll

...

tlmarques by L4 Transporter
  • 238 Views
  • 3 replies
  • 1 Likes

Resolved! Cortex XDR Windows 11 ARM64 Support?

Is there a plan or timeline for XDR being supported on Windows 11 with ARM64?

I have a customer getting the error message "this version of Cortex XDR can be installed only on x64 architecture systems, please use the appropriate installation package."

pdysart by L1 Bithead
  • 3559 Views
  • 8 replies
  • 1 Likes

XDR Analytics Data source

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Analytics-Alert-Reference-by-data-source/BitLocker-key-retrieval https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Analytics-Alert-Reference-by-data-source/Exchange-mailb

...

Cortex XDR- Compromise Assessment

Hi, we recently moved to Cortex XDR, and I’m struggling to run a forensic script (such as AmCache) across 100 endpoints. I need to have all the results automatically combined into a single Excel sheet after the script finishes, similar to how Fidelis

...

Requesting Cortex XDR Demo

How can I get a cloud demo for Cortex XDR? I’ve tried requesting one, but I haven’t received any email back from Paloalto.

https://www.paloaltonetworks.com/cortex/request-demo 

 

Cortex XDR 

AAlsaadi by L1 Bithead
  • 137 Views
  • 0 replies
  • 0 Likes

XDR CIE

How is CIE configured in XDR MSSP? Is it only on the parent and then shared to child tenants or can it be configured differently on each of the child tenants?

Installing Cortex Agent on Linux LXD

 

Hello everyone,

I am looking to install the Cortex Agent on a Linux system within an LXD container. Does anyone have insights or a step-by-step guide on how to install the Cortex Agent in this environment?
Additionally, is Cortex officially supported

...

  • 2286 Posts
  • 86 Subscriptions
Top Solution Authors
Top Liked Authors