Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4322 Views
  • 0 replies
  • 3 Likes

Searching for multiple hashes on cortex XDR

Does anyone know a way to search for multiple hashes on Cortex XDR? file_search = existing_files does not allow any operators other than "=" for the sha values and you can't string multiple in a query. I feel like I'm missing something and there should be a way to do that that I'm not aware of. Any ideas?

rufat87 by L2 Linker
  • 4868 Views
  • 3 replies
  • 0 Likes

Confirmed issues with some identity threat modules and risk management dashboard

Hello everyone! Recently, I have been learning about the Identity Analytics feature in Cortex XDR. After enabling Identity Analytics, I found that not every tenant presents the same interface. I found that the following UI features are not identical: absence of a Risk Management Dashboard less information displayed in User Risk View (e.g. Reg...

Chilla by L1 Bithead
  • 2972 Views
  • 3 replies
  • 0 Likes

Changing cortex installation directory in Linux

Hi All, Need some help! We have a Linux instance where the opt/ folder size is 2 GB and the recommended disk quota by Cortex is 5 GB. We can not resize it. Do anyone know if there is a way to change the installation directory of Cortex from /opt to any other folder? Awaiting your response, thanks in advance!.... Biswajit.

Resolved! Error (0x800705b4) during installation of 7.5 CE on W7/S2008R2

Hi everyone, unfortunately we still have a bunch of W7/S2008R computers (without extended support) in our network. The majority of the pcs have Cortex XDR 7.9 installed. In terms of support we are now trying to uninstall 7.9 and install 7.5 CE instead. The problem is, the installation only works on about 10% of the mentioned clients, at the re...

Sorting out generic website fw rules

Hey everyone,We are trying to sort out generic firewall alerts that we get as the incidents. Currently, when there's site blocked that someone browsed through, we get the incident to check for it.I would like to implement some correlation rule that will only trigger alert for suspicious ad/website when there are more than 1 connection, especiall...

Resolved! Cortex XDR Licenses

Hello, Could you please share the required detail and if possible share documentation related it.? How are licenses utilized in Cortex XDR? (user based or device based) - How are new agent IDs created? (Parameters for agent Id creation) Deployment method

What is /opt/traps/analyzerd/clad?

Hello We run several Linux Servers with XDR on it. 11 out of those Linux Zoo, we get an Insident of our Monitoring, claiming, that there are double processes running: 3587 /opt/traps/analyzerd/clad -n clad -c 197:requests -- --log-level 7 --max-worker-count 10 What is clad, why is it not running on other Linux machines, how may we close th...

Access to live terminal with dual control

For legal reasons in our organization we have servers that can only be accessed in administrator mode if another authorized person authorizes access. That is, under no circumstances can a single person get administrator permissions. Following this policy, we would like to continue to have Live Terminal functionality on these machines but with du...

Folder and File exclusions wildcard question

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-a-New-Malware-Security-Profile The docs says: (Optional) Add files and folders to your allow list to exclude them from the examination. +Add a file or folder. Specify the path and press Enter or click the check mark when done. You can also use a ...

  • 2589 Posts
  • 95 Subscriptions
Top Solution Authors