Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Test Custom BIOC Rules

Hi Expert,

 

Please help me to create custom BIOC rules for the testing.

My company want to create rules bioc informational if We create/delete spesific file in spesific folder, and the information will appears in incidents.

Is it possible? 

If is it poss

...

Resolved! Uninstall vs Using Agent Cleaner

When an IT admin uninstalls Cortex XDR from an endpoint does it remove that endpoint from the XDR Console?

When they use the Agent Cleaner to remove XDR from an endpoint does it remove that endpoint from the XDR Console?

We are running into duplicate e

...

pdysart by L1 Bithead
  • 3758 Views
  • 1 replies
  • 0 Likes

Resolved! Notification CORTEX compatibility

Hi, We received a PA notification about Microsoft Windows 10 version 21H2 running on specific hardware architectures are incompatible with a security engine in Cortex XDR agent 7.0.0 – 7.4.0. In our case we have the following scenario:

- Cortex agent

...

BigPalo by L4 Transporter
  • 2511 Views
  • 1 replies
  • 0 Likes

XDR Linux agent - what is the dypd process?

What is the purpose of the dypd process?

 

sudo /opt/traps/bin/cytool runtime query
 Name PID User Status Command
pmd 32757 root Running /opt/traps/bin/pmd
analyzerd 534 474 Running /opt/traps/analyzerd/analyzerd 71 73 75
dypd 517 root Running /opt/traps/b

...

KarenW by L0 Member
  • 3379 Views
  • 1 replies
  • 0 Likes

XDR command line scan

Hi All, I've been looking at the functionality of the cytool command line and cannot find a way to scan a particular file, which is available if you right click the file in Windows. Can anyone tell me if the ability to scan an individual file, or fol

...

  • 1926 Posts
  • 79 Subscriptions
Top Liked Authors