Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4546 Views
  • 0 replies
  • 3 Likes

Cortex XDR: Excluding Specific AI Agent PowerShell Activity While Maintaining Blocking

Currently, PowerShell activity generated by an AI Agent is being detected by Cortex XDR. After investigation, we confirmed that this activity is a false positive, as the AI Agent uses PowerShell for administrative/management purposes. Due to our internal operational policy, we cannot use Legacy Exceptions, so we are considering using Exclusion R...

.522643 by L1 Bithead
  • 64 Views
  • 1 replies
  • 0 Likes

Create an issue when FIM events detected

Hello experts, We plan to get the FIM module on top of my XDR. Having set up with FIM Profile and Policy, we could be able to see those events successfully. with the following information: 2. Dataset and Presets for FIM Dataset: xdr_data XQL Filter:dataset = xdr_data | filter fim_event = true Console: Inventory → Endpoints → File Integrity...

XDR Alert Dump – Finding the File That Triggered the Alert

I have a question. When we perform a Dump Alert and get the ZIP file, how can we analyze it in more detail? For example, if I want to see the .ps1 file that a particular user executed on the machine and that triggered the alert, would that file be included in the dump? I’ve already searched everywhere, but I can’t find it. I can see a folder cal...

tlmarques by L4 Transporter
  • 79 Views
  • 1 replies
  • 0 Likes

Resolved! Low Incident

We have integrated Cortex XDR with Elastic SIEM. Our SOC process currently creates a ticket for every Cortex XDR incident/case, including Low, Medium, and High severity incidents. Is Palo Alto's recommended best practice to create tickets for all Low severity incidents, or should Low severity alerts/incidents be monitored and correlated before t...

R.Abdeen by L0 Member
  • 144 Views
  • 1 replies
  • 0 Likes

XDR 4 - Integrations AD Query

Hi everyone, on Cortex XDR 4 ,we can build small playbooks, and one of the available actions is AD Query.My question is: what is required to configure this integration? I see that the integration asks for the IP address, domain user, and other parameters, but if the Active Directory is on-premises, how does Cortex XDR establish the connection?Wh...

tlmarques by L4 Transporter
  • 1950 Views
  • 4 replies
  • 0 Likes

XDR agent reboot recover everytime

Hi guys, Recently, we identified several computers running Cortex XDR version 9.2.0.120 with Content Version 2340-38788. After the machines start, connect to the tenant, and receive the latest content/information, they start rebooting approximately every minute. The Windows message displayed is: “You’re about to be signed out”“Reinício agendado...

tlmarques by L4 Transporter
  • 83 Views
  • 0 replies
  • 0 Likes

Cortex XDR JDP method instrumentation causing severe Java runtime slowness (agent 9.2.0.120) — follow-up to solved cyjagent crash thread

This is a follow-up to a previously solved thread: Cortex XDR cyjagent.dll injection causes JVM startup crash, where @susekar confirmed the known JDP/JVM conflict (CPATR-38467 / CPATR-18158). Thanks for that confirmation. Since the solution there is already accepted, raising this as a separate topic: we've now observed a second symptom from the ...

Non-Persistent VDI – File Collection and Investigation with XDR

Hi everyone, I need some help/advice. I’ve been seeing some cases on non-persistent VDIs where we receive alerts such as “Script Engine Activity - 3121803131”. Basically, the Cortex XDR alert is related to an HTML file hosted on a ShareFile share that I don’t have access to. From what I understand, the HTML file is essentially a web-page templat...

tlmarques by L4 Transporter
  • 42 Views
  • 0 replies
  • 0 Likes

Predicting blocked alerts when switching Malware/Exploit modules from "Report" to "Block"

Hi everyone, We are currently in the process of fine-tuning our Cortex XDR tenant. At the moment, we have several modules within our Malware and Exploit security profiles set to "Report" mode. We are planning to harden our security posture and switch these modules to "Block" mode. However, before making this change, we want to assess the potenti...

Cortex XDR – Automatically Resolve Alerts/Issues as "Known Issue" Using Playbook or Predefined Command

Hello Team, We are using a Cortex XDR tenant and would like to know whether there is a supported way to automatically update an alert/issue resolution to "Known Issue" using a predefined command, automation, or playbook action. Our goal is to avoid manual analyst intervention for alerts that have already been validated as known benign activity a...

Disable legacy automation rules

Hello, Currently in our xdr tenant, many issues have been getting automatically closed by legacy automation rules, rules migrated from XDR v3.x to v5,x. The problem is that these rules have conditions such as, category=Malware and detection method = XDR Agent whichr esults in legitimate security incidents being closed without analyst review. ...

Resolved! Cleanup XDR Endpoints

How can we clean up (delete/remove) the old endpoints that are still registered on Cortex XDR ? Is there any automation available for this, or do we need to remove them manually?

tlmarques by L4 Transporter
  • 183 Views
  • 1 replies
  • 0 Likes

Resolved! Cortex XDR cyjagent.dll injection causes JVM startup crash (EXCEPTION_ACCESS_VIOLATION in ntdll.dll)

We run an enterprise Java server application (Zulu OpenJDK 11, Windows Server) and are seeing consistent JVM crashes at startup on hosts protected by Cortex XDR. The agent injects cyjagent.dll (Java Deserialization Protection module) into the Java process, and the JVM crashes in native code: # EXCEPTION_ACCESS_VIOLATION (0xc0000005) # Problem...

Resolved! SBAC for DLP add-on

Hello All, Would SBAC also works for DLP (add-on) module events? We wou ld enable SBAC for those Endpoints with DLP enable by department. Then allow each department head as the Data Security Reviewer to view their own DLP events. Possible to do so? Thanks, SDH

Real-Time BIOC Detection and Playbook Execution for SSH/RDP Sessions

Hello, I am working on a Playbook to detect RDP/SSH communications between servers and automatically terminate the corresponding process when such communication is detected. As a preliminary test, I have configured a small-scale test to verify that the process can be automatically terminated. My current configuration is as follows. 1. XDR Enviro...

.522643 by L1 Bithead
  • 107 Views
  • 1 replies
  • 0 Likes
  • 2654 Posts
  • 101 Subscriptions
Top Solution Authors