Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4402 Views
  • 0 replies
  • 3 Likes

Cortex XDR Checkin Time

Hello All, Was curious, is there a related registry key for Traps last check-in date? I'm curious if there is an easy way to pull in that information with powershell. Quick example scenario would be that we would use one script to pull in the last check in time with multiple computers with Cortex XDR. Thanks!

Amnsgna by L0 Member
  • 3217 Views
  • 3 replies
  • 0 Likes

Changing Analytics and BIOC Analytics Rules Severity and Configuring the Agent to Block

Hello all, I have identified that the Analytics and BIOC Analytics is identifying real threats yet no action has been initiated due to the log source. Is it possible to increase the severity of these rules to Medium and higher ? Secondy, is it possible to set the policy to block when identifying these specific rules on the XDR Tenant? From what...

XQL - what am I doing wrong?

Hello dear community! I am testing some XQLs from the last webinar. In my test I fired following XQLs one on one, but I do not understand why the left join doesn't work. I allways get 7 results with the host inventory users preset. Without I get 12 results with 10 unique Users. --XQL Begin config case_sensitive = false| dataset = xdr_data| f...

RFeyertag by L4 Transporter
  • 3591 Views
  • 3 replies
  • 0 Likes

Resolved! XDR agent install using SCCM

Hi All, I would like to know if it's possible to install a new agent over an existing agent on a workstation. We have a specific situation where we enabled the auto-upgrade feature in our environment, but excluding our POS devices. To address the POS devices needing agent upgrades we're thinking of leveraging SCCM or some other automated appl...

Documentation for Advanced API Monitoring

Dear LIVE community, Does anyone have any details on Advanced API monitoring? (Under Malware profile --> Global Behavioral Threat Protection Rules) It is disabled by default and the only information we got so far was that it could help detect CVE-2023-23397. Please share if you got any supporting document from Palo as I couldn't find any ...

Resolved! Query for listing installed VPN's in organization

Hey everyone,I'm trying to list all devices within organization that have installed some VPN on them, but my query fails each time or returns small number of results. I set it to have most popular 10 VPN's in the list like Nord, OpenVPN, Express, Cyber Ghost etc.Could you please help me out in adjusting query, to list hostname of the devices and...

Resolved! Cortex XDR Host Firewall behavior Question

Hi Everyone, I am trying to configure host firewall using Cortex XDR, in the documentation, it mentions: The Cortex XDR host firewall rules leverage the operating system firewall APIs and enforce these rules on your endpoints, but not your Windows or Mac firewall settings. Device Control • Cortex XDR Prevent Administrator Guide • Reader • Pa...

AmmarJi by L1 Bithead
  • 5104 Views
  • 4 replies
  • 1 Likes

Resolved! Cortex XDR Live Terminal Session - Can you disable the agent notification?

I'm looking for a way to disable the little notification pop-up that occurs on the endpoint when a security tech opens a live terminal session through the console, but I haven't been able to find anything in the tenant settings or KB articles so hoping somebody here can help. Anybody know if this is possible? Thanks!

KaWright by L0 Member
  • 5709 Views
  • 1 replies
  • 0 Likes

Resolved! Agent Upgrade Failure

Hi, These are agent upgrade failure reasons, please suggest the method to resolve these issues- 1- Installer has timed out 2- Cortex Agent upgrade failed 3-The content package was faulty or could not be downloaded. Thanks Shahwaz

  • 2612 Posts
  • 98 Subscriptions
Top Solution Authors
Top Liked Authors