Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

GoToMeeting Whitelist

Does anyone know how to whitelist the GoToMeeting download?

 

It is an EXE but the client agent blocks it.  When I attempt to whitelist it, EVERY SINGLE download is a different hash value making it impossible to whitelist.

 

Thanks for any suggestions.

FIltering for Content Version

Palo recently issued a security bulletin where we are protected if we have Content Update 150.  I was trying to add a filter for "< 150-39463" to only see those endpoints that might not have checked in for a bit.  The 7.1 documentation does not show

...

Work with an email attachment

Hello community,

 

I'm facing some problems in order to work with the attachment of potential phishing cases. The phishing button that we have configured sends the original email as an attachment without format. Which is making XSOAR read it like that:

...

Sergio_Gonzalez_0-1607505981146.png
Sergio_Gonzalez_1-1607506152397.png

Bitlocker recovery keys not present

Hello,

I wanted to check if someone can shed some light on this issue I had.

 

During a Cortex XDR PoC, the end user activated the Disk encryption policy on a couple of workstations without confirming the pre-requisities so these workstations encrypted

...

Resolved! Accessing Files While Scanning

Hello, this might be a dumb question but I'm trying to find any documentation that might back it up.

 

Basically, when conducting a system scan some apps can't be executed because they try to access certain .dll files which are being used or are open b

...

Authentication BIOC rule

Currently, I can create one-off or scheduled queries for authentication data / events but not BIOC rules which isn't ideal because scheduled queries don't create incidents.

 

Is it on the roadmap to add this ability?

 

Thanks.

2020 ∕ 09 ∕ 22 15꞉28꞉02 - Query_Builder_-_Cortex_XDR_-_Google_Chrome.png
2020 ∕ 09 ∕ 22 15꞉30꞉54 - Rule_Builder_-_Cortex_XDR_-_Google_Chrome.png

Timeframes for BIOC rules

It'd be very useful for things like failed logons or network connection attempts if BIOC rules could utilise timeframes.

 

Is this on the roadmap?

 

It could work well if this was done in a similar way to NGFW → OBJECTS → Custom Objects → Vulnerability →

...

2020 ∕ 09 ∕ 23 10꞉52꞉33 - PA_LAB_-_Google_Chrome.png

Demisto : How to display List of Messages

Hi Team, I am using create_incident API to create incidents. Below is the sample code. I can create an incident when I use "messages" as String.  Basically, this is custom_fields and its data vary from incident to incident.  Some incidents may have 

...

Screenshot from 2020-10-22 22-29-37.png
JSannake by L0 Member
  • 2238 Views
  • 1 replies
  • 0 Likes

Mitre ATT&CK techniques missing

After reading https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-release-notes/release-information/features-introduced/features-introduced-in-2020.html#ide2559432-5eb3-4f83-8e85-c4159aeed9ed → "MITRE Tags Enhancements", I retroactively ad

...

2020 ∕ 09 ∕ 22 16꞉15꞉16 - BIOC_-_Cortex_XDR_-_Google_Chrome.png
2020 ∕ 09 ∕ 22 16꞉15꞉27 - Hide_Artifacts,_Technique_T1564_-_Enterprise__MIT.png

Resolved! SaaS Log Collection

Can't find SaaS Log Collection to start ingesting external logs into Cortex XDR.
 
All the documentations state: Click Gear > Settings > SaaS Log Collection
I can't find it, I currently have Cortex XDR Pro Per Endpoint, does this license not support ing
...

Web filtering in Cortex?

Hello,

 

We have just recently implemented Cortex XDR for endpoint protection and have a question about web filtering.  Are there profiles/polices in Cortex XDR that can enable any web filtering features or is web filtering strictly a firewall feature?

...

bsuprai by L0 Member
  • 5054 Views
  • 1 replies
  • 1 Likes
  • 1810 Posts
  • 78 Subscriptions
Top Solution Authors
Top Liked Authors