Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4434 Views
  • 0 replies
  • 3 Likes

Resolved! XDR agent install using SCCM

Hi All, I would like to know if it's possible to install a new agent over an existing agent on a workstation. We have a specific situation where we enabled the auto-upgrade feature in our environment, but excluding our POS devices. To address the POS devices needing agent upgrades we're thinking of leveraging SCCM or some other automated appl...

Documentation for Advanced API Monitoring

Dear LIVE community, Does anyone have any details on Advanced API monitoring? (Under Malware profile --> Global Behavioral Threat Protection Rules) It is disabled by default and the only information we got so far was that it could help detect CVE-2023-23397. Please share if you got any supporting document from Palo as I couldn't find any ...

Resolved! Query for listing installed VPN's in organization

Hey everyone,I'm trying to list all devices within organization that have installed some VPN on them, but my query fails each time or returns small number of results. I set it to have most popular 10 VPN's in the list like Nord, OpenVPN, Express, Cyber Ghost etc.Could you please help me out in adjusting query, to list hostname of the devices and...

Resolved! Cortex XDR Host Firewall behavior Question

Hi Everyone, I am trying to configure host firewall using Cortex XDR, in the documentation, it mentions: The Cortex XDR host firewall rules leverage the operating system firewall APIs and enforce these rules on your endpoints, but not your Windows or Mac firewall settings. Device Control • Cortex XDR Prevent Administrator Guide • Reader • Pa...

AmmarJi by L1 Bithead
  • 5184 Views
  • 4 replies
  • 1 Likes

Resolved! Cortex XDR Live Terminal Session - Can you disable the agent notification?

I'm looking for a way to disable the little notification pop-up that occurs on the endpoint when a security tech opens a live terminal session through the console, but I haven't been able to find anything in the tenant settings or KB articles so hoping somebody here can help. Anybody know if this is possible? Thanks!

KaWright by L0 Member
  • 5772 Views
  • 1 replies
  • 0 Likes

Resolved! Agent Upgrade Failure

Hi, These are agent upgrade failure reasons, please suggest the method to resolve these issues- 1- Installer has timed out 2- Cortex Agent upgrade failed 3-The content package was faulty or could not be downloaded. Thanks Shahwaz

using XDR to block older versions of an application

I'm attempting to use XDR to block older versions of an application, and only allow the few latest releases. There are hundreds of older versions of this application so blocking each one by hash is not really an option. Also the application's install path and process executable have the same name with every version so blocking by path or executa...

Resolved! Decoupling an alert from an incident

I have seen a few instances where an alert is incorrectly linked to an incident - for example, an incident might have 50 alerts from one host and only 1 from a second host, where the alerts don't appear for a common activity. The alerts are reasonably valid, just not really related to one another. In cases like this, I'd like to split off the...

Forensics Addon - Best practise licence and usage

Hello dear community, how do we use this addon? I had found a article about the forensics addon which said, you can also put this feature to an client/server after the incident etc. happened.What is the difference between having this addon for all our servers/clients active or to put this profile to our client/server after a real incident which...

RFeyertag by L4 Transporter
  • 6175 Views
  • 6 replies
  • 1 Likes
  • 2624 Posts
  • 98 Subscriptions
Top Solution Authors
Top Liked Authors