Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4337 Views
  • 0 replies
  • 3 Likes

Resolved! Connector from XDR and AWS portal

Hello, Is there a way to create a connector between cortex console and AWS portal that can fetch EC2 information as soon as the agent comes online and then populate the data received by this connector into the XDR. Thanks !

NivedaR by L2 Linker
  • 2711 Views
  • 2 replies
  • 0 Likes

Cortex XDR Auto update mechanism

Does anyone know the Cortex XDR Auto update mechanism?I recently found that some agents failed to update automatically. The failed content included content update and agent update. The console log did not give the reason for the failure. What are the reasons for the update failure? How often will the content update be triggered again after a fai...

Grady by L2 Linker
  • 5297 Views
  • 6 replies
  • 0 Likes

Behavioral Threat alerts for sdiagnhost.exe spawning cronhost.exe - false positive?

Hi community, Wondering if anyone else is seeing BT alerts for sdiagnhost.exe appearing over the last 24 hours? We have had similar things occur in the past due to over excited signature updates cause false positives. This process is one that MSDT Follina uses but the servers it popping up on do not run any Office products running so confident...

Incident question - svchost without signature?

Hello dear community, you know how to handle this svchost.exe without signature? In my opinion it is FP, but why? Isn't it possible for the cortex agent to read the signature from svchost.exe in this case? I tweaked the alert and gave it medium severity and some more applications. BR Rob

RFeyertag_0-1659806957154.png
RFeyertag_3-1659807299644.png
RFeyertag by L4 Transporter
  • 3108 Views
  • 3 replies
  • 0 Likes

Global Rule a4978720-39fc-404f-bb74-c3db07ef4f9d - ISO mounted manually questions

Hello dear community, in my mount tests I could find out following: - if you mount the same file name 2 times with different file data inside the iso, the alert isn't created because the file isn't beeing created. I think the recent folder is not made for this, because the lnk file stays there. - when mounting via cmd.exe no lnk file is cr...

RFeyertag by L4 Transporter
  • 2437 Views
  • 3 replies
  • 0 Likes

Alert when a XLL was created/read/deleted

Hello dear community, what is the best way to setup a query for bioc to get an alert. Maybe correlation rule is a better place for my project? It should alert, when a XLL File was written or read or deleted. Should I setup a specific file location in my query or is this not neccasary and I can take any file location? I ask because of the resso...

RFeyertag by L4 Transporter
  • 1624 Views
  • 1 replies
  • 0 Likes

Resolved! XQL - New attacks through ZIPs and ISOs

Hello dear Community, has someone of you a ready to implement XQL Query for downloading zip/rar/iso file containing a iso? The source can be outlook, etc. I found a sigma rule based on: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file_event/file_event_win_iso_file_mount.yml I would be appreciate for some examples. BR Rob

RFeyertag by L4 Transporter
  • 5662 Views
  • 6 replies
  • 0 Likes

Automatic status assigning of Incidents

Hello, The Resolved- False Positive incidents are automatically getting assigned to Under Investigation even though there are no updates or alerts regarding the incident. The above keeps on repeating every day. Any idea why this is happening and how do we avoid it? Thanks

Aiman_Fathima_0-1659698513781.png

DTRH: Scripting Anything and Reaping Data

DTRH: Scripting Anything and Reaping Data Overview Customers are always asking for additional capabilities in the product and often times these feature request may come during a POC where having that capability can be the deciding factor in winning the deal. The feature request to delivered into the product can be a long cycle, often time you ...

JEbrahimi_0-1622052573092.png
JEbrahimi_1-1622052573097.png
JEbrahimi_2-1622052573099.png
JEbrahimi_3-1622052573100.png

Resolved! Alert from which source/rule?

Hello! We have some alerts which show us a large upload. My problem is now, I saw other clients uploading a ton of bytes, but this Alert wasn't fired. I also cannot find any Rule for this. Where is it comming from? BR Rob

RFeyertag_0-1659634616953.png
RFeyertag by L4 Transporter
  • 3751 Views
  • 3 replies
  • 0 Likes

Resolved! Cortex XDR block explorer.exe, network interfaces and other programs - PC (Windows) isn't usable

Dear Live Community Members, I have an issue and I'm struggling to find the reason behind it and need your help. To give you some background on the problem at hand, my customer installed the Cortex XDR agent, and it works fine on some machines but on others when the installation process finished the problem occurred immediately and the PC is...

Resolved! XQL query with multiple values

Hello Community, I'm been using the platform for a couple months and recently I'm getting interested in XQL query. My question is how to I simplify the search string if i have multiple values that I need to insert?With the example below, i'm looking to simply the filter section to filter action_device_usb_vendor_name "vendor_A, vendor_B, vendo...

  • 2593 Posts
  • 97 Subscriptions
Top Solution Authors