Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 755 Views
  • 0 replies
  • 2 Likes

Malware Scans on Linux Endpoints

Hi Team,

Can you please confirm we can run malware scans on linux servers and linux virtual appliances? We want to create a policy in XDR to run periodic malware scans on the servers (Specially linux servers and linux virtual appliances). 

Regards,
Saks

...

Cortex XDR blocks MalwareBytes

After a recent update to MalwareBytes Cortex XDR is now detecting and blocking it.

 

Has anyone else seen this, and is there a was to allow the MalwareBytes Digital Signature? I prefer not to have to allow the hash for each version.

 

GaryM_0-1739887323265.png
GaryM by L0 Member
  • 273 Views
  • 1 replies
  • 0 Likes

Resolved! XQL query for all datasets

What's the fastest way to get a list of all data types by product and vendor across all data sets? I am looking for a way to query internal logs of XDR to get a list of all types of logs that are getting ingested into the XDR instead of using wildcar

...

XQL/BIOC - web

 

Hello,

 

Can you tell me in which dataset I can find the following data?

  • URL addresses
  • User Agent

With this information, can we create a rule that is based on defined values ​​and then generate an alert based on it or block it within the Restriction

...

arekf by L1 Bithead
  • 342 Views
  • 2 replies
  • 0 Likes

Cannot update user role to another user

This is about user permssion settings, I'm already the account admin of the XDR tenant already.
Currently, the user scope is set to all, i want to change the scope for specific user.
But there is no update user permission when right click on user 
does

...

XQL Timeseries Chart

I'm trying to build a timeseries chart that counts alert volume per day and that fills in zero values for days with no data. I have the following XQL that populates days with data but I'm unable to fill in a zero for all other days between now and th

...

XDR Agent - retrieve more information events

Hi,

I have a question. I'm seeing XDR events with "Memory Corruption Exploit" generated by the XDR Agent... Cortex XDR 

 

I know this typically happens when users open a DOCX file with macros. My question is: Is there a way to collect information rel

...

tlmarques by L4 Transporter
  • 358 Views
  • 1 replies
  • 0 Likes

Broker VM - Local Agent Settings Applet Error

Hi Team,

As observed, we're getting the below error in the local agent settings applet in our broker vm's. We have three broker vm's in place and all of them are showing the same error. We have not made any changes in the configurations. Could you ple

...

SKhurana_0-1739781898751.png

Resolved! Cortex XDR folder taking up space

Hello Cortex Team,

 

On one of our server endpoint, the Dump folder located on the path : ProgramData\Cyvera\LocalSystem\Dump is taking a lot of space.

 

We already tried to clear the database of said agent, no difference. (see screenshot before and

...

  • 2284 Posts
  • 86 Subscriptions
Top Solution Authors
Top Liked Authors