Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Can Cortex XDR be installed to be standalone?

We're in a situation where HQ has moved to Cortex XDR, at the satellite facilities, there are PC/Laptops that never touches HQ network and are often standalone systems or is on a competely separate domain and those domain is to never communicate with

...

Vudoo408 by L0 Member
  • 2525 Views
  • 1 replies
  • 0 Likes

Endpoint disconnected - Admin console

I am having issues with an endpoint connecting to the Cortex XDR dashboard,

The Cortex XDR console from within the OS is showing as 'Enabled' however it is disconnected from the endpoint administrator console.

 

I have attempted restart the services usi

...

KirkH by L0 Member
  • 2542 Views
  • 1 replies
  • 0 Likes

Windows version 21H2 - Cortex incompatibility

Hi,

 

We received a PA notification about Microsoft Windows 10 version 21H2 running on specific hardware architectures are incompatible with a security engine in Cortex XDR agent 7.0.0 – 7.4.0.

 

In our case we have the following scenario:
- Cortex agent

...

BigPalo by L4 Transporter
  • 3218 Views
  • 3 replies
  • 0 Likes

Live Terminal over Broker VM

Hello everybody.

 

I want to know if we can initiate a live terminal session over Broker VM ( our agents dont have internet access so they use Broker VM ). 

1) In documentation Palo Alto say that network requirements for Broker VM are these:

     - br-<X

...

Memory Corruption Exploit Alerts - Incidents

Hello LiveCommunity, I wondered if any others are seeing a very high number of recently created (in the last few hours) "Memory Corruption Exploit" alerts in Cortex XDR?

Beginning around 1015 Pacific this morning (11 Oct) thru as recent at 1518 Pacifi

...

XDR Cloud Identity Engine and proxy

Hello everybody,

 

We want to integrate our Active Directory to Cortex XDR via Cloud Identity Engine. But there must be proxy between Cloud Identity Engine and Cortex servers. We setup a lab environment for test purpose ( simply forwarded web traffic v

...

XDR vs XSOAR

Hello people ,

 

I am trying to figure out real difference between XDR and XSOAR.

 

XDR is far more intelligent than. SIEM . So this means SIEM is killed ?

 

XDR can also perform incident response , so what is the real value of SOAR?

Resolved! Cortex XDR client preventing Windows boot

Our organization has started using Azure AD and Intune for managing PCs, and the enrollment include the deployment of Cortex XDR client. So far, we've had no issues during our (slow but surely) transition.

But last week I encountered a strange problem

...

XDR Client version 7.5.0 High Memory Usage

We recently upgraded our XDR Clients from 7.4.2 to 7.5.0. Since the upgrade a lot of our Windows Servers seem to be using a lot more memory that what I recall other client versions using. For example, older versions where like 200-400MB of usage but

...

mbahen by L2 Linker
  • 11604 Views
  • 13 replies
  • 0 Likes

Alert USB activity

Hi community,

 

Can I check is there any one create a alert if a user copied more than a certain number of files into a USB drive?

Thank You, Cheers!

BoonHwee by L1 Bithead
  • 2377 Views
  • 1 replies
  • 0 Likes
  • 1798 Posts
  • 78 Subscriptions
Top Solution Authors