Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Cortex XDR with Citrix App Layering and MCS

We're in the process of installing a new setup with Citrix App Layering (Full User layers) and MCS. I've followed the suggestions here on non-persistent installation (VDI_ENABLED=1); even though our setup technically is sort of persistent (because of

...

BocoIP by L1 Bithead
  • 5642 Views
  • 4 replies
  • 0 Likes

Endpoint Connection Lost

Hi all,

 

Some of our endpoints in our Cortex XDR Console shows  a "Connection Lost" Status but the endpoint is still active.

The cytray shows disabled and no connection. We also checked the control panel and upon checking, The installed Cortex XDR Agen

...

EJaspe by L1 Bithead
  • 2130 Views
  • 2 replies
  • 0 Likes

Cortex XDR disk encryption

Hello,

 

I can't turn off disk encryption. I disabled the disk encryption policy for an endpoint, then the encryption status returned as not configured. But I can still see bitlocker on the endpoint is ON. How can I turn off bitlocker on endoint not ma

...

CIDR Lookup or Join for IP Enrichment

I would like to use some custom datasets to enrich some of our XQL searches.  It could be our subnets from our IPAM or in this example the ASN information.  I have used lookups and joins in the past to accomplish this in others tools and would like t

...

Verdict of VT and WildFire

Hello Team,

 

From XDR console, we wanted to export alerts includes verdict from WildFire and Virus Total which we are not getting.

 

Can anyone help me with XQL query or other way to get verdict (for e.g. Process: Excel.exe WF Verdict: Benign and VT sco

...

  • 2054 Posts
  • 81 Subscriptions
Top Solution Authors