Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4361 Views
  • 0 replies
  • 3 Likes

XQL Query: Issue with arrayindexof() function in host_inventory dataset

Whenever we use arrayindexof() function with host_inventory dataset we get an error (Failed to run) but whereas when we run with dataset of xdr_data we get a success response message. Please run the below XQL query: (Status == Success) config case_sensitive = false | dataset = xdr_data | alter sampleArray = arraycreate("ABC","DEF","GHI","JKL"...

How to find the Cortex XDR client Policy Profile name from Windows without Local Admin

As different Cortex XDR Policy profiles can be pushed to different users, it is sometime required to find out what is the current XDR Policy Profile used by a particular endpoint. If the endpoint has local administrator privilege, we could just search in the *.ldb files in the following folder for the name of the profile used.C:\ProgramData\Cy...

tingmy by L1 Bithead
  • 3252 Views
  • 2 replies
  • 0 Likes

Please share your useful XQL queries!

Hello! as a beginner with Cortex XDR I asked me, what are interests of others in the query section. If you have some interesting and useful queries, please share and describe them in a short way. Thank you! BR Rob

Cyber1985 by L3 Networker
  • 13050 Views
  • 4 replies
  • 2 Likes

Resolved! Support File Password

We used to be able to access endpoint files and now the zip is asking for a password. Is this the 'admin password' setup under agent settings?

eumbach_0-1677098454680.png
eumbach by L3 Networker
  • 6749 Views
  • 1 replies
  • 0 Likes

Resolved! Reboot Date & Time through python script

Hello dear community, I wan't to check the boot time of server OS, because of windows updates. When they got installed and the system is not booted, it will get to an unstable status. This is a small script, which is reading the fqdn, hostname and reboot time. import socket import psutil import datetime # returns the time in second...

RFeyertag by L4 Transporter
  • 3409 Views
  • 3 replies
  • 0 Likes

False Positive: Suspicious File Modification' generated by XDR Agent - Module Anti-Ransomware Protection

Hi we see a problem with a powershell Script we are using to clean up Profiles on some specific Remote Session Host Servers.It will be blocked by Cortex XDR Pro and so I want to make an Exception for this. Unfortunately it seems only possible to do an Alert Exception for this and so it will allow the Initiator CGO "Powershell.exe"for the Ransomw...

How many attempts constitute a brute force attempt?

Occasionally, I see an alert with the description of "LDAP: User Login Brute Force Attempt". If I'm reading the tea leaves correctly, we're relatively confident that we're observing a failed logon for someone performing maintenance on a specific device. But it would be nice to know what Cortex constitutes as a "brute force attempt". Is it th...

Cortex XDR Agent Driver Shutdown on Windows 11 22H2

Hello Team, We have received an advisory for Cortex XDR Agent Driver Shutdown on Windows 11 22H2. Its was recommended that to pause any planned upgrades on endpoints running the operating system Windows 11 22H2. It was also mentioned that a new installer for versions supporting Windows 11 22H2 will be made available in the upcoming days and...

how to suppress the prompt "Cortex XDR" would like filter network content"

for the Macs, how does one configure Cortex to suppress the display of this prompt (see attached), and just automatically use 'Allow'. Ive tried calling up com.paloaltonetworks.cortex.app.plist, but I don't see an obvious key pair where this behavior might be controlled. Please note you are posting a public message where community members a...

Resolved! XQL query to find agents seen in the last 30 days

Hi, I am looking to create a report that will list all endpoints seen in the last 30 days. I have created an XQL query that will return all endpoints but I am not able to filter this query to limit the scope to agents that have been seen in the last 30 days ONLY.-------------------------------config case_sensitive = false| dataset = endpoints| f...

Wildfire Test File

Has anyone had issues with the Wildfire Test file not showing up as an alert in the cloud? On the workstation it's getting blocked just fine. I haven't had a regular alert fire in about 2 months. Just wondering if I have an underlying communication issue. Also looked at the logs to verified no proxies are setup.

Resolved! Symantec Uninstall or disable and Enable Cortex

All Thanks in advance for help We have Cortex in Report/Audit mode and Symantec Endpoint protect in block mode . We want to enable Cortex for Block mode and either disable or uninstall Symantec . Has anybody have got any advice or experience with this ? Symantec has a cleanwipe tool however its a GUI and does not have command line options ...

Balaraju by L2 Linker
  • 4643 Views
  • 3 replies
  • 0 Likes

Limitations Cortex XDR Pro with Threat Intelligence Feeds

Hello dear community, I'd like to know more about how you fill your IOCs in Cortex XDR Pro. There are so many TI Feeds outside: https://www.comparitech.com/net-admin/best-threat-intelligence-feeds/ I'd would prefer the low cost variant (XDR Pro is not the cheapest one). Here are my questions: 1. Does Cortex XDR Pro offer a API for uplo...

RFeyertag by L4 Transporter
  • 2627 Views
  • 2 replies
  • 0 Likes
  • 2601 Posts
  • 98 Subscriptions
Top Solution Authors
Top Liked Authors