Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4361 Views
  • 0 replies
  • 3 Likes

Resolved! Disable Scheduled Scans on non-persistent VDI machines

In our environment we are using Cortex XDR. We are at the point where we want to start looking at maybe installing this on non-persistent virtual desktops. I found the documentation that talks about how to install on the master image but there was also mention of disabling scheduled scanning on the virtual desktops. I do not have access to the c...

Resolved! Cortex XDR - Brute force alert rule

Hi, I need to create a brute force rule. When endpoints with tag "CRITICAL" has "action_evtlog_description = An account failed to log on" and has more than 50 logs, create a CRITICAL alert. Could you help pls. Regards,

Resolved! Enable Endpoint File Scanning Documentation - Clarification

Hello - On step 16 of Add a New Malware Security Profile (Prevent), there is a note: We recommend that you disable scheduled scanning. VDI machine scans are based on the golden image and additional files will be examined upon execution. I'm assuming based on the the second sentence that this only applies to VDI machines. It is throwing me of...

Automation of Reports

Hello Team, We need to create automated XDR report to detect executions of “Python.exe” and “PowerShell.exe & PowerShell_ise.exe” in our environment. Can we query a incident/alerts to make a report or suggest us how we can generate reports based on the above requirements. Can we configure a scheduler in this report so that all the intende...

Resolved! Palo Alto BIOC rule content error [specific rule]

Hello, There is an issue with one of the BIOC rules provided by Palo Alto. Specifically in the rule with Global ID "94fed992-c1da-4b69-9caa-292221b8c070". The wildcards for the command line arguments that this rule intents to detect, are off. To be precise all leading wildcards in this detection have a space afterwards, thus rendering the rule u...

ithermos by L1 Bithead
  • 2579 Views
  • 2 replies
  • 0 Likes

Resolved! XDR API File Retrieval

Hello, I'm trying to connect an integration with our Cortex XDR for retrieving a file and its details. The only endpoint I see in the API docs that reference this action is the File Retrieval Details which uses the group_action_id from a different API request "Retrieve File" However, I am unable to find the docs on the Retrieve File endpoint...

Kevhardy by L0 Member
  • 3122 Views
  • 2 replies
  • 0 Likes

Resolved! Powershell Script and XDR

There is a PowerShell script that we would like to use within XDR. I understand that XDR currently is not able to run PowerShell scripts, the problem is I am not a coder. I have been trying to learn how to convert our script to Python but I am just about to give up. In my research, I found some posts from users on various websites explaining t...

Performance Issues update from 7.9.0.20664 to 7.9.1.26645

Hello dear Community! We habe seen, the updgrade on 7.9.1.26645 or a following policy update changed something on our server with DB and Application. Our application (DB on the same machine) is much slower, than before 07.03. Every step takes now much longer than before. Does anyone else have issues like this? BR Rob

RFeyertag by L4 Transporter
  • 2364 Views
  • 2 replies
  • 0 Likes

Licence Cortex XDR Pro

Hello dear community, I know now, if you have less licences than installed agents, somehow they are degraded to Prevent. Can we see somewhere which one is degraded to Prevent version? How is degrading happen and where can I see it? BR Rob

RFeyertag by L4 Transporter
  • 1406 Views
  • 1 replies
  • 0 Likes

XQL Query: Finding Location of Public IP based on iploc command.

We are trying to find out ASN number, Organization Name, Location, City, Country for public IPs. Below is our query just in case: Note: The query which we ran is applied on interface which are receiving public facing IPs. We filtered that part of the query. config case_sensitive = false | dataset = panw_ngfw_threat_raw | fields rule_matched...

KanwarSingh01_0-1678149273362.png
  • 2600 Posts
  • 98 Subscriptions
Top Solution Authors
Top Liked Authors