.zip files Cortex XDR PRO
Hi community,
Can cortex detect and analyze .zip files with password and delivered via email?
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.
Hi community,
Can cortex detect and analyze .zip files with password and delivered via email?
After reading https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-release-notes/release-information/features-introduced/features-introduced-in-2020.html#ide2559432-5eb3-4f83-8e85-c4159aeed9ed → "MITRE Tags Enhancements", I retroactively ad
...
Hello Friends,
Does anyone knows how can we send the Mitre ATT&CK information/reference from Cortex XDR Alerts via Syslog?
The default configuration does not have this reference.
Hello,
We have just recently implemented Cortex XDR for endpoint protection and have a question about web filtering. Are there profiles/polices in Cortex XDR that can enable any web filtering features or is web filtering strictly a firewall feature?
...
Hello,
We are an existing Palo customer and we are moving to Cortex XDR for our Antivirus solution. In our current AV application we have groups for different clients based on exceptions or application for various reasons. It is very easy to create i
...
Hi Community,
Does Cortex XDR support to be installed on Windows 10 20h2?
Thanks!
Hi Community,
I am unable to upgrade the Traps agent from v5.0.x to 7.2 using the rule from XDR console. I have upgraded from 6.0. Not sure whether my antivirus is blocking it.
I can see the version is showing as upgraded in the console for a while th
...
Hi All,
Cortex XDR agent consuming my full resource while scanning. Did anyone face this kind of issue?
I am using another endpoint(Symantec) in the same workstation. Planing to whitelist the cortex XDR folder from Symantec. Please share which are th
...
It appears that Cortex XDR does not play well with the existing encryption product we use. There is no indication of any issues whatsoever, but when you attempt to decrypt the drive the application is not successful at decrypting all of the files.
...
I was reading about the new Bitlocker functionality in the new release. We have Bitlocker already deployed in the organization and would like to know if I could use the CortexXDR console as only a "view" or status into the status of Bitlocker on alre
...
Does anyone have a Grok filter compatible with Cortex XDR syslog entries?
I'm piping Cortex XDR syslog into logstash and then through to Elasticsearch for parsing & alerting, but there seems to be two nested log formats. One pipe-separate and then in
...
Good morning,
I'm running into issues trying to update the cortex agent on some of our physical machines running Win 10.
I'm very new to Cortex so I apologize if there's issues with my explanation of what I'm having issues with.
Inside my endpoint ad
...
Hello I am new to Cortex XDR. I tried ncat on a PC with Cortex XDR Prevent (with Windows Defender) and it did not detect or stop the connection from Kali a PC. Windows Defender showed a warning and once I allowed it I was able to connect on ncat from
...
Hello,
does anyone know if it is possible to exclude an entire folder on a Windows machine from Cortex XDR scan in order to launch executable files without being blocked and having to add the file hash to the whitelist ?
User | Likes Count |
---|---|
5 | |
4 | |
3 | |
2 | |
2 |