Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4322 Views
  • 0 replies
  • 3 Likes

Playbook to enrich dataset data into alert context

Hi, Is anyone able to guide me on how to achieve this perhaps? I want to ran a task in a playbook that will do a custom query in a dataset and pull information and add it to the alert context data.. is this possible and if so guidelines would be appreciated. thanks in adv

PA_nts by L4 Transporter
  • 721 Views
  • 1 replies
  • 0 Likes

Cortex XDR – Unable to Assign Read/Write Permissions for Mobile Device (Detected as CD-ROM) in Permanent Exceptions

I am working on a Cortex XDR Device Control configuration and I need to allow a specific mobile device only for file transfer from the endpoint to the device, but I do not want to allow any data transfer from the mobile device back to the endpoint. However, I noticed that the device is detected as a CD-ROM device type in Cortex XDR (1.ss). When ...

MErkenci_4-1766488381566.png
MErkenci_5-1766488412968.png
MErkenci_0-1766488660359.png

Restrict traffic to public IP addresses with Cortex

I have dual homed systems with one of the IP addresses being publicly routable due to a cellular connection. My goal is to use Cortex to block traffic destined to those public IPs. An XQL query has been constructed to match traffic I would like to block, and I have created a BIOC that meets the intent as well, however I'm not seeing that BIOC as...

How to escape a wildcard (*)

How could you escape a wildcard in a query For example if i am looking for suspicious LDAP queries like (objectclass=*), i need that to be literal and not match on things like objectclass=example. I have tried many different combinations including just a simple \* but have not found anything that works

Resolved! Exclusion process cortex?!

Hi,How can I create an exclusion in Cortex XDR to stop it from scanning a specific executable?? We have a critical software in our company, and we've noticed that Cortex is constantly analyzing it, causing the machine high CPU and MEM.How can we exclude this file from the analysis? We want to maintain protections such as Ransomware, just excludi...

tlmarques by L4 Transporter
  • 4236 Views
  • 5 replies
  • 0 Likes

Resolved! Force XDR Agent

Hello, Please, how to force XDR Agent to capture all commands on CMD and PowerShell without GPO? For example, we can detect quser command, but we can't detect Set-Alias command. The problem is another vendor can detect any command line running in memory. Best regards.

Resolved! I want to block commands and special operations that require administrator privileges on Windows.

Hi Experts, As stated in the title, I want to block commands and special operations that require administrator privileges on Windows. Is this achievable? Please tell me the necessary configuration method to achieve this (I couldn't find it when I searched, but I'd appreciate any documentation or knowledge pages). Thank you.

woody249 by L4 Transporter
  • 2248 Views
  • 2 replies
  • 0 Likes

Cortex XDR Blocking Intel process

Hello,We have noticed a reoccuring issue between our clients, that a intel process is being blocked.The main cause of it being blocked is IntelGraphicsSoftware.Service.exe with a path something like this - C:\Program Files\WindowsApps\AppUp.IntelArcSoftware_25.40.1953.0_x64__8j3eq9eme6ctt\VFS\ProgramFilesX64\Intel\Intel Graphics Software\IntelGr...

Please update MITRE Techniques in BIOC module

Please update MITRE Techniques available in BIOC creation menu for Cortex XDR V3.16 Missing MITRE techniques in BIOC module: T1204.004 - User Execution: Malicious Copy and Paste - https://attack.mitre.org/techniques/T1204/004/ T1204.005 - User Execution: Malicious Library - https://attack.mitre.org/techniques/T1204/005/ I am sure these aren'...

D.Ogle by L0 Member
  • 1088 Views
  • 0 replies
  • 0 Likes

XDR 4 - default playbooks error

Hi, someone have Cortex XDR 4? i my case, i've adopted some playbooks, and all playbooks have problems with configuration. Configuration using old json values (context values), for example:incident.id and correct is issue.id etc etc

tlmarques by L4 Transporter
  • 411 Views
  • 0 replies
  • 0 Likes

Resolved! Broker VM shown disconnected

Hi, our Broker VM is shown disconnected on XDR console. The VM is up and running and I can connect to it via SSH. It can connect to the paloaltonetworks.com domain as I can see the traffic on firewall. Version is 25.0.44. Even the last seen is today, but the VM keeps shown disconnected. We have had similar problems with thin clients agents but t...

  • 2589 Posts
  • 95 Subscriptions
Top Solution Authors