Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4321 Views
  • 0 replies
  • 3 Likes

Resolved! Agent Upgrade Failure

Hi, These are agent upgrade failure reasons, please suggest the method to resolve these issues- 1- Installer has timed out 2- Cortex Agent upgrade failed 3-The content package was faulty or could not be downloaded. Thanks Shahwaz

using XDR to block older versions of an application

I'm attempting to use XDR to block older versions of an application, and only allow the few latest releases. There are hundreds of older versions of this application so blocking each one by hash is not really an option. Also the application's install path and process executable have the same name with every version so blocking by path or executa...

Resolved! Decoupling an alert from an incident

I have seen a few instances where an alert is incorrectly linked to an incident - for example, an incident might have 50 alerts from one host and only 1 from a second host, where the alerts don't appear for a common activity. The alerts are reasonably valid, just not really related to one another. In cases like this, I'd like to split off the...

Forensics Addon - Best practise licence and usage

Hello dear community, how do we use this addon? I had found a article about the forensics addon which said, you can also put this feature to an client/server after the incident etc. happened.What is the difference between having this addon for all our servers/clients active or to put this profile to our client/server after a real incident which...

RFeyertag by L4 Transporter
  • 5868 Views
  • 6 replies
  • 1 Likes

Cortex XDR don't alert when using WinPeas.bat

Good morning,We have noticed that when using LinPEAS on Linux systems, Cortex XDR reacts, blocks and alerts. However, using WinPEAS bat script on Windows systems is not detected by Cortex. However winpeas.exe is blocked immediately. For testing purposes we used linpeas.sh and winpeas.bat from: carlospolop/PEASS-ng: PEASS - Privilege Escalation ...

wbpdki by L0 Member
  • 2909 Views
  • 1 replies
  • 0 Likes

Sharing various xql queries

This returns dns queries filtered by the domain name given in the variable. config case_sensitive = false | preset = network_story | filter (dns_resolutions != null) | arrayexpand dns_resolutions | alter Resolution_Value = dns_resolutions -> value{}, Resolution_Name = dns_resolutions -> name{}| fields agent_hostname, actor_process_image_...

Domain Controller can't connect to the Broker VM for Windows Event Collector

Hi All, we are facing an Issue with the WEC on the Broker VM. We configured the Domain Controller and enabled the WEC on the Broker VM. We followed the installation guide which is refered in the Cortex XDR. The Domain Controller shows in the log the following error. "The SSL certificate could not be checked for revocation. The server use...

Resolved! IOC Upload through API - Expiration date

Hello dear community! my ps script is ready to upload IOCs. One of my questions how fast the expiration date eraser is triggered in the dashboard? In the last case it took two days. This one is still active, but the expiration date is in the past. How can this be? BR Rob

RFeyertag_0-1682894028775.png
RFeyertag by L4 Transporter
  • 2619 Views
  • 4 replies
  • 0 Likes

Resolved! Run Endpoint Script - registry_get

Hi all, I try to run registry_get in the action center, but always fails to run. I check the administrator guide and learned that doesn't seem to work when running specific hives (e.g. /HKEY_CURRENT_USER/ ) So I try to get some registry information in \HKEY_LOCAL_MACHINE\SYSTEM\Cyvera, the content of this script mentions support for accepting ...

Chilla by L1 Bithead
  • 3117 Views
  • 2 replies
  • 0 Likes

Resolved! Cortex XDR and Windows Snipping Tool

On Windows 11 with both Cortex 7.9.1 and the most recent 8.0 version when users use the Snipping tool to take a screenshot, the whole computer freezes and only the mouse works, users have to CTRL-ALT-DEL and logout to get working again. When Cortex XDR is removed then the Snipping tool works as expected, as anyone else had this and if so how did...

  • 2585 Posts
  • 95 Subscriptions
Top Solution Authors