Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 420 Views
  • 0 replies
  • 2 Likes

Resolved! Bitlocker Encryption Status Only

I was reading about the new Bitlocker functionality in the new release. We have Bitlocker already deployed in the organization and would like to know if I could use the CortexXDR console as only a "view" or status into the status of Bitlocker on alre

...

hhiggins by L2 Linker
  • 8650 Views
  • 8 replies
  • 0 Likes

Grok Filter for Syslog entries

Does anyone have a Grok filter compatible with Cortex XDR syslog entries?

 

I'm piping Cortex XDR syslog into logstash and then through to Elasticsearch for parsing & alerting, but there seems to be two nested log formats. One pipe-separate and then in

...

Resolved! Updating Cortex Agent 7.2 fails

Good morning,

 

I'm running into issues trying to update the cortex agent on some of our physical machines running Win 10. 

I'm very new to Cortex so I apologize if there's issues with my explanation of what I'm having issues with.

 

Inside my endpoint ad

...

Cortex XDR Prevent Did Not Detect ncat

Hello I am new to Cortex XDR. I tried ncat on a PC with Cortex XDR Prevent (with Windows Defender) and it did not detect or stop the connection from Kali a PC. Windows Defender showed a warning and once I allowed it I was able to connect on ncat from

...

Cortex XDR folder exclusion

Hello,

does anyone know if it is possible to exclude an entire folder on a Windows machine from Cortex XDR scan in order to launch executable files without being blocked and having to add the file hash to the whitelist ?

Resolved! Force policy check in Cortex XDR

Hi,

 

Is there any way to force a policy check on an endpoint?

 

I have created a new Policy Rule and assigned a new set of Policy Profiles to it.  I then assigned specific endpoints to this Policy Rule and the rule is #1 in the policy order tab.

 

The pro

...

Cortex XDR Alerts - Slack Integration

Is there any way to include the hostname for alerts received in Slack? They are very valuable to receive on the phone late at night, but would be even better if we had a bit more information: hostname, domain, something that indicates this is a test

...

Exceptions "Child process"

Hello!!

 

How are you?  i need confirm an action when add exception for child process, i have several alerts for "WmiPrvSe.exe Rare Child Process" that are false positive, and im considering add to whitelist in the profile associated.

 

 

For create it i

...

Julitro_0-1598461562310.png
Julitro by L0 Member
  • 2824 Views
  • 1 replies
  • 0 Likes

Resolved! Extend Ransomware Protection to SMB Shares

I noticed that my tenant space has a new option in the Windows Malware Profile under Ransomware Protection that is named "Extend Ransomware Protection to SMB Shares".  I don't believe this setting was available prior tot he 7.2 release that I read ab

...

  • 2212 Posts
  • 86 Subscriptions
Top Solution Authors
Top Liked Authors