Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4396 Views
  • 0 replies
  • 3 Likes

Join two data sets XQL

Before I get into my failed script, please allow me to explain what Im attempting to do. We are looking for windows and Macintosh devices with cortex xdr agent NOT installed. To do this we installed the cortex DHCP log collector. It is reporting its findings into asset manager. The problem is that when an IP changes, the agent doesnt show this...

Modifying Policies and Profiles on XDR

Dear All, I wanted to create an XQL Query to identify the modification of XDR policies or Profiles by anyone who have access to XDR, so that I wanted to get the list of users who tried to modify the policies or profiles. I wanted to convert the XQL query into a report and can schedule it as a weekly report. Can someone help me to write a q...

VenuK by L2 Linker
  • 2320 Views
  • 2 replies
  • 0 Likes

Auto Agent Upgrade in 3.6 version

Hello Team, Since the new version of Cortex has come out 3.6 version. Wanted to get clarity on auto -the agent upgradation part. Is it recommended to upgrade your agents(servers/workstation) to N-1 or latest version via auto agent upgrade policy?' If yes then can you help in collecting information for below mentioned Q's' 1.What to do if ...

File search based on Host

Is there any option in Cortex XDR, where we can check which all hosts have a specific exe present? For eg We want to get a list of hosts which has google chrome installed in it. Regards, Shashank

Resolved! Agent script Library

Hello, I would like to know if a script to that invokes live terminal or other functions related to Cortex XDR can be done using agent script library.

NivedaR by L2 Linker
  • 3813 Views
  • 4 replies
  • 0 Likes

Resolved! Intense SSO failures

Hello everyone,Recently after the update we started getting errors for SSO that say Intense SSO failures.While investigating execution chain, I only ran into outcome reason as "Strong authentication is required or device authentication failed".Is there anything else we can investigate here, is this something we need to worry about or?Best regards.

Agent Blocking files/processes dynamically based on conditions

Hello XDR Enthusiasts, I am working with multiple XDR Tenants and would like to block a file/process based on conditions. I understand that you can use the Prevention features to block files based on a block/black list. This can also be configured on the Malware Profile settings where specific severity incidents can induce the agent to block the...

Outlook stops syncing with Cortex XDR enabled

We have 2 Cortex tenants with a total of about 600 users. We encountered an issue where Outlook 365 will show "Needs password" and will not connect to Office 365 to sync. The only way to get it to sync is to stop the Cortex service. Once Outlook connects, you can enable it again, and be fine for a day or two, then it will do it again. I'm not 1...

Resolved! Disable Scheduled Scans on non-persistent VDI machines

In our environment we are using Cortex XDR. We are at the point where we want to start looking at maybe installing this on non-persistent virtual desktops. I found the documentation that talks about how to install on the master image but there was also mention of disabling scheduled scanning on the virtual desktops. I do not have access to the c...

Resolved! Cortex XDR - Brute force alert rule

Hi, I need to create a brute force rule. When endpoints with tag "CRITICAL" has "action_evtlog_description = An account failed to log on" and has more than 50 logs, create a CRITICAL alert. Could you help pls. Regards,

  • 2611 Posts
  • 98 Subscriptions
Top Solution Authors
Top Liked Authors