Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4322 Views
  • 0 replies
  • 3 Likes

XDR on old MacOS unable to check in

hi all, I am trying to install XDR client on the old MacOS like, El capitan, mojave and High Sierra. But the 7.x version weren't able to install so i generated 5.0.6 installation package and manage to install to the above mentioned OS. But after the installation, my endpoints are not able to check in and update their policies. And the option...

Mingwei by L0 Member
  • 2869 Views
  • 3 replies
  • 0 Likes

Resolved! Missing function Virus Total check

Hello dear community, since today we are missing the point of departure virustotal in the APP GUI. It is not possible to launch this function in the incident anymore. Except via Quick Launcher. Is this a bug or a feature? BR Rob

RFeyertag_0-1659963855040.png
RFeyertag by L4 Transporter
  • 7345 Views
  • 10 replies
  • 0 Likes

Resolved! Cortex XDR Tags with logo

Dear All, I configured some tags while the installation of the the agent on the workstations, they have the logo attached. But I need now to change some tags or remove them using Cortex XDR management console. I tried Manage Endpoint Tags (paloaltonetworks.com) this method,but it works only for all the tags created on the console since they ...

Resolved! Connector from XDR and AWS portal

Hello, Is there a way to create a connector between cortex console and AWS portal that can fetch EC2 information as soon as the agent comes online and then populate the data received by this connector into the XDR. Thanks !

NivedaR by L2 Linker
  • 2704 Views
  • 2 replies
  • 0 Likes

Cortex XDR Auto update mechanism

Does anyone know the Cortex XDR Auto update mechanism?I recently found that some agents failed to update automatically. The failed content included content update and agent update. The console log did not give the reason for the failure. What are the reasons for the update failure? How often will the content update be triggered again after a fai...

Grady by L2 Linker
  • 5286 Views
  • 6 replies
  • 0 Likes

Behavioral Threat alerts for sdiagnhost.exe spawning cronhost.exe - false positive?

Hi community, Wondering if anyone else is seeing BT alerts for sdiagnhost.exe appearing over the last 24 hours? We have had similar things occur in the past due to over excited signature updates cause false positives. This process is one that MSDT Follina uses but the servers it popping up on do not run any Office products running so confident...

Incident question - svchost without signature?

Hello dear community, you know how to handle this svchost.exe without signature? In my opinion it is FP, but why? Isn't it possible for the cortex agent to read the signature from svchost.exe in this case? I tweaked the alert and gave it medium severity and some more applications. BR Rob

RFeyertag_0-1659806957154.png
RFeyertag_3-1659807299644.png
RFeyertag by L4 Transporter
  • 3094 Views
  • 3 replies
  • 0 Likes

Global Rule a4978720-39fc-404f-bb74-c3db07ef4f9d - ISO mounted manually questions

Hello dear community, in my mount tests I could find out following: - if you mount the same file name 2 times with different file data inside the iso, the alert isn't created because the file isn't beeing created. I think the recent folder is not made for this, because the lnk file stays there. - when mounting via cmd.exe no lnk file is cr...

RFeyertag by L4 Transporter
  • 2430 Views
  • 3 replies
  • 0 Likes
  • 2587 Posts
  • 95 Subscriptions
Top Solution Authors