Cortex xdr did not detect malware, what good is it?
Cortex XDR did not detect malware, what good is it?
I got this scan with mal warebytes. 41 detected.
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.
Cortex XDR did not detect malware, what good is it?
I got this scan with mal warebytes. 41 detected.
Hi all,
Do you all know what the best simulated malware is to use in testing out rules/responsiveness/etc on Cortex XDR and where to download these fake malware from. Ideally it'll be benign specially constructed so they trigger same alerts as actual
...
We have deployed more than 800 agents in the network. Currently, we have a trial license but they will purchase the license the next month.
If the actual license will come did we have to again reinstall the agents.
Hi Team,
After installing cortex XDR, I can see C:\ProgramData\Cyvera\Prevention folder is getting filled up fast in one of the servers. There are a lot of activities on this server and Traps is catching some malicious activities often. This will def
...
Hello ,
We are using Cortex XDR Prevent 3.2 with 2 Broker VMs for Proxy access .
I guess Broker VMs are Linux appliance . So is there any way to find the Linux kernel version which these VMs are running ?
Thanks in advance for response
Is anyone monitoring XdrAgentCleaner execution? And if so i have a question, lets say when we run the XdrAgentCleaner, before the agent cleans all the Cortex traces, does it sends the EDR telemetry to cloud so in case if XdrAgentCleaner is used malic
...
Hi there,
I am just getting started into what Cortex XDR can do. One item I cannot find a clear answer to so far is how XDR handles alerts forwarding or some API integration between it and, for example, Freshdesk/ServiceNow/Autotask etc.
Is this poss
...
Hi guys,
We get a lot of false positives from Wildfire where it's reporting custom applications used on a "business as usual" (BAU) basis in our environment. Do you folks know if there are settings from the Wildfire backend that Palo Alto normally ad
...
Hi everyone,
As we know that XDR agent can block the execution of any particular executable files but can anyone let me know whether XDR agent can block the download of any particular executables like winrar.exe, ccleaner.exe, etc. from any source li
...
Hello!
As I know, samples which are provided to VT, are "lost" in the endless VT world. VT can do with the files what they want. (Sharing, etc.).
When we connect Cortex XDR with VT, what will be transfered to VT?
What are the limitiations with Cortex
...
Hello everyone,
Would like to know your recommended best practices for post-implementation/management of Cortex XDR pro for Endpoint and TB.
Also, it will be also great if you can share a KT document for it.
Thanks
Is it safe to install paloalto cortex XDR solution?
If we install in our premises then our client machine data may get compromised if cortex scan for malware on cloud. Then what is the use of proxy broker server. I want my data must be safe and it sh
...
Hello,
We would ike to know if it is possible to create a list of IP's that will not be analysed by any of the XDR protection modules.We have a vulnerability scanning tool that uses all sorts of scripts to perform its tasks, At the moment, most of th
...
Hi
Anyone successfully ingest logs from Cisco ISE to Cortex XDR via syslog?
I've activated the syslog collector of broker VM for TCP514 and format set to auto detect, following this documentation, and configured the Cisco ISE to forward the logs to
...Subject | Likes |
---|---|
1 Like | |
1 Like | |
1 Like | |
1 Like | |
1 Like |