Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4321 Views
  • 0 replies
  • 3 Likes

Deploying Cortex XDR via AutoPilot

I've been trying to configure Cortex XDR version 8.0.1.33809 to be deployed when configuring a laptop with autopilot. I downloaded the agent directly from Cortex XDR, configured it with the intune app creator to convert from an .msi file to a .intunewin file and uploaded and configured the app in Intune. When the computer is being setup, Cortex ...

Resolved! System Threshold exception BIOC rules

I have once upon a time set the system threshold exception to 100 hosts. So when the same BIOC is triggered on 100 hosts at the same time, it automatically creates an exception. I would like to raise the number of hosts, but I cannot find the place to change this setting. It is nowhere to be found. I seem to recall it being a setting in a menu o...

DavidStevens_0-1684748059771.png

Cortex XDR Checkin Time

Hello All, Was curious, is there a related registry key for Traps last check-in date? I'm curious if there is an easy way to pull in that information with powershell. Quick example scenario would be that we would use one script to pull in the last check in time with multiple computers with Cortex XDR. Thanks!

Amnsgna by L0 Member
  • 3054 Views
  • 3 replies
  • 0 Likes

Changing Analytics and BIOC Analytics Rules Severity and Configuring the Agent to Block

Hello all, I have identified that the Analytics and BIOC Analytics is identifying real threats yet no action has been initiated due to the log source. Is it possible to increase the severity of these rules to Medium and higher ? Secondy, is it possible to set the policy to block when identifying these specific rules on the XDR Tenant? From what...

XQL - what am I doing wrong?

Hello dear community! I am testing some XQLs from the last webinar. In my test I fired following XQLs one on one, but I do not understand why the left join doesn't work. I allways get 7 results with the host inventory users preset. Without I get 12 results with 10 unique Users. --XQL Begin config case_sensitive = false| dataset = xdr_data| f...

RFeyertag by L4 Transporter
  • 3409 Views
  • 3 replies
  • 0 Likes

Resolved! XDR agent install using SCCM

Hi All, I would like to know if it's possible to install a new agent over an existing agent on a workstation. We have a specific situation where we enabled the auto-upgrade feature in our environment, but excluding our POS devices. To address the POS devices needing agent upgrades we're thinking of leveraging SCCM or some other automated appl...

Documentation for Advanced API Monitoring

Dear LIVE community, Does anyone have any details on Advanced API monitoring? (Under Malware profile --> Global Behavioral Threat Protection Rules) It is disabled by default and the only information we got so far was that it could help detect CVE-2023-23397. Please share if you got any supporting document from Palo as I couldn't find any ...

Resolved! Query for listing installed VPN's in organization

Hey everyone,I'm trying to list all devices within organization that have installed some VPN on them, but my query fails each time or returns small number of results. I set it to have most popular 10 VPN's in the list like Nord, OpenVPN, Express, Cyber Ghost etc.Could you please help me out in adjusting query, to list hostname of the devices and...

Resolved! Cortex XDR Host Firewall behavior Question

Hi Everyone, I am trying to configure host firewall using Cortex XDR, in the documentation, it mentions: The Cortex XDR host firewall rules leverage the operating system firewall APIs and enforce these rules on your endpoints, but not your Windows or Mac firewall settings. Device Control • Cortex XDR Prevent Administrator Guide • Reader • Pa...

AmmarJi by L1 Bithead
  • 4847 Views
  • 4 replies
  • 1 Likes

Resolved! Cortex XDR Live Terminal Session - Can you disable the agent notification?

I'm looking for a way to disable the little notification pop-up that occurs on the endpoint when a security tech opens a live terminal session through the console, but I haven't been able to find anything in the tenant settings or KB articles so hoping somebody here can help. Anybody know if this is possible? Thanks!

KaWright by L0 Member
  • 5573 Views
  • 1 replies
  • 0 Likes
  • 2585 Posts
  • 95 Subscriptions
Top Solution Authors