Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 3549 Views
  • 0 replies
  • 3 Likes

API for exceptions?

Hi,
looking for API for adding exceptions, is it exists ?

I'd like to add programmatically exceptions which are done by UI > Settings > Exception Configuration > Legacy Agent Exceptions > Add Rule

 

ITApps by L0 Member
  • 337 Views
  • 1 replies
  • 0 Likes

Correct Way to Add Cortex Exclusions

Often, we get requests from application admins and their vendors to exclude an application or folder from the anti-virus or security software. In the past, we have entered these requests into the Allow List of the related Malware Profile (which has b

...

Resolved! Installing Cortex Agent on Linux LXD

 

Hello everyone,

I am looking to install the Cortex Agent on a Linux system within an LXD container. Does anyone have insights or a step-by-step guide on how to install the Cortex Agent in this environment?
Additionally, is Cortex officially supported

...

Pass-the-Ticket - PtT

Hi guys, 

I’d like to know if anyone already has a detection rule configured in XSIAM correlation for a Pass‑the‑Ticket attack.
I’m building a rule from scratch, but it’s not as effective as I’d like.

If anyone has a ready‑made rule or some solid ide

...

Brew package manager for MacOS

We utilise Brew for package manager for our Mac in our organisation and we have over 100+ engineers using it to manage their operating environment. Cortex doesnt pick up any of the applications installed via brew or any of the vulnerabilities associa

...

Resolved! Exfiltration Simulation/Testing

I was wondering if anyone has good procedures or methodology for simulating various kinds of data exfiltrations. We have a handful of rules related to exfiltration but have not established a meaningful way of assuring they are functional and sufficie

...

M.Crow by L1 Bithead
  • 5366 Views
  • 3 replies
  • 0 Likes
  • 2520 Posts
  • 93 Subscriptions
Top Liked Authors