Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by • Community Team Member
  • 4601 Views
  • 1 replies
  • 3 Likes

Create a IOC without incident

Good morning, Today I would like to create a block for two malicious files that I found in our environment. I noticed that I can create an IOC to block paths, file names, IPs, etc. I have already created an IOC using a wildcard for the file name: PDFEditor_*.exe, but I would also like to block the process without generating an incident. Is that ...

Resolved! XDR add more values to incident classification

Hi everyone, When I close each incident, I need to add the CSIRT taxonomy flags (from the ENISA Reference Incident Classification Taxonomy: https://www.enisa.europa.eu/publications/reference-incident-classification-taxonomy) to the Cortex XDR case. Does anyone know if that is possible?

tlmarques by • L4 Transporter
  • 1781 Views
  • 4 replies
  • 0 Likes

Resolved! Cortex Management Report

I want to know if I can generate a report of Cortex's actions over the last year or 3 months, such as what he blocked, quarantined, isolated, etc., but in a graph format. I tried using a widget library, but I can't find a way to represent that action. What can I do?

XDR 5.0 - opinion

Cortex Cortex XDR 5.0 tenant. What's your opinion https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-5.x-Release-Notes/Release-Information

tlmarques_0-1770656806817.png
tlmarques by • L4 Transporter
  • 2850 Views
  • 8 replies
  • 0 Likes

Resolved! High Bandwidth on Broker VM: Cluster Mismatch (v29 vs v28) & P2P

Hi everyone, I'm facing high bandwidth usage on my Primary Broker VM. I need to validate if my diagnosis is correct: The Setup: Cluster: HA Pair. Node 1 is v29.0.77 (Healthy). Node 2 is v28.0.99 (Service "Local Agent Settings" is Red/Down). Policy: Download Source = Broker VM (P2P is currently disabled). My Questions: Cluster: Does the v...

Resolved! Correlating a file path to application inventory

Hello, I am gathering an application inventory for endpoints in our environment. As part of this inventory, I'd like to include the install path for these applications. Currently Host Inventory XQL dataset only showcases uninstall strings in the applications field. Assistance in correlating an install path via joining datasets or something si...

Resolved! Sending USB Alerts via syslog (Cortex XDR)

Hello, We have received a request asking whether it is possible for administrators to receive alert emails whenever a USB device is connected to any endpoints.(*Currently, the USB policy in Exploit – Device Configuration is set to Read Only.) (* I think the adminster wants to get the log [Inventory-Device Control Violations]) We attempted to c...

YSONG464633_0-1770612974843.png

Resolved! Microsoft Photos.exe

Hi, Does anyone experience receiving alerts from photos.exe due to "Suspicious File Modification" and the Module is "Anti-Ransomware Protection" even the program is legitimate?Other factors I'm seeing is due to possibly outdated version of the said program. *See attached reference photo*I'm hoping from anyone's advice from other members with the...

J.Indoc by • L0 Member
  • 2512 Views
  • 2 replies
  • 0 Likes

Request for Query to Retrieve Endpoint Security Details.

Hi Team, I would like to create a query that provides the following information for endpoint security events: Severity Artifact type (e.g., executable files or other relevant artifacts) Endpoint name IP address Windows OS version Action taken (e.g., Block or Alert) Cortex Agent versionTimeframe: I will be set manually Cortex XDR ...

Brew package manager for MacOS

We utilise Brew for package manager for our Mac in our organisation and we have over 100+ engineers using it to manage their operating environment. Cortex doesnt pick up any of the applications installed via brew or any of the vulnerabilities associated with them and only detects anything once its in a running state. This seems like a very basic...

Vulnerability assessment report

Hello, In viewing this report I've noticed its still flagging servers that have been patched already and wondering how often that checks against all endpoints? I can go on a server and its not showing any updates needed and then look in the report and its in there showing it needs 68 updates which all come from a cumulative update (windows) but ...

Notepad++ block specific hash version

Guys, Does anyone know if it is possible to block the hashes associated with older versions of Notepad++? My goal is to allow only Notepad++ version 8.9.1 to be executed, and to block the installation and execution of all other versions.

tlmarques by • L4 Transporter
  • 2399 Views
  • 3 replies
  • 0 Likes
  • 2660 Posts
  • 102 Subscriptions
Top Solution Authors
Top Liked Authors