Cortex XDR Threat Hunting Community
Hi All,
Is there there threat hunting community for Cortex XDR?
Cheers
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.
Hi All,
Is there there threat hunting community for Cortex XDR?
Cheers
Is there a way we can analysis the dump file when a behavior based alert is generated for an incident? We would like to analysis the process dump file with volatility for windows 10 machines.
Thanks for the help in advance.
How to check receive log from fortigate VM64 on VM broker syslog collector?
I setup log fortigate VM64 pattern as by Cortex xdr manual but no log from FortiGate send to Cortex Data Lake.
Currently, BIOC rules can be created for "NETWORK" (endpoint-based) or "NETWORK CONNECTIONS" (NGFW-based) but only the latter supports the usage of App-ID and VPN infrastructure isn't always in place or available.
Are there any plans to add this?
During a recent investigation our team came across a situation where we needed to take a forensic image of a device on our network. Prior to taking the image, we had hoped to utilize Live Terminal in order to remotely capture a memory dump to get a h
...
Does anyone know how to whitelist the GoToMeeting download?
It is an EXE but the client agent blocks it. When I attempt to whitelist it, EVERY SINGLE download is a different hash value making it impossible to whitelist.
Thanks for any suggestions.
Palo recently issued a security bulletin where we are protected if we have Content Update 150. I was trying to add a filter for "< 150-39463" to only see those endpoints that might not have checked in for a bit. The 7.1 documentation does not show
...
Hello community,
I'm facing some problems in order to work with the attachment of potential phishing cases. The phishing button that we have configured sends the original email as an attachment without format. Which is making XSOAR read it like that:
...
Hello,
I wanted to check if someone can shed some light on this issue I had.
During a Cortex XDR PoC, the end user activated the Disk encryption policy on a couple of workstations without confirming the pre-requisities so these workstations encrypted
...
Hello, this might be a dumb question but I'm trying to find any documentation that might back it up.
Basically, when conducting a system scan some apps can't be executed because they try to access certain .dll files which are being used or are open b
...
Our company just got this Cortex endpoint protection but it seems to me like it is just a endpoint management software that was able to detect a few malware. Anyone have experience with traps or cortex?
Currently, I can create one-off or scheduled queries for authentication data / events but not BIOC rules which isn't ideal because scheduled queries don't create incidents.
Is it on the roadmap to add this ability?
Thanks.
It'd be very useful for things like failed logons or network connection attempts if BIOC rules could utilise timeframes.
Is this on the roadmap?
It could work well if this was done in a similar way to NGFW → OBJECTS → Custom Objects → Vulnerability →
...
Hi Team, I am using create_incident API to create incidents. Below is the sample code. I can create an incident when I use "messages" as String. Basically, this is custom_fields and its data vary from incident to incident. Some incidents may have
...
Hi All
We are receiving large number of alerts in our cortex xdr console, The alert is as below, (hostname and user name I have kept as XYZ for privacy)
'Kernel Privilege Escalation' generated by XDR Agent detected on host XYZ involving user XYZ"
In
...Subject | Likes |
---|---|
4 Likes | |
4 Likes | |
4 Likes | |
2 Likes | |
2 Likes |