Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4361 Views
  • 0 replies
  • 3 Likes

Removable Media Extension Profile

I wanted to get everyone else's 2 cents here and see how other people are doing it. My goal here is to prevent writing data to unapproved removeable media but allow reading. I created an device configuration extension profile with disk drives set as read only a few months ago a tested and it functioned as expected and blocked writes to my unappr...

How to make console accessible to domain user?

Hello! I'm new around here and I have a question.How to make Cortex XDR console to be accessible only to domain users?So only users connected to the domain network can access the Cortex XDR Console.It'd be very helpful if you provide related documentation or guide. Thanks in advance!

Resolved! Cortex Blocks system services

Hello everyone,the problem started a day ago, when Cortex XDR started to trigger the behavioral rule "other.malware_gen_task.105" on the service"System", when executing the child processes "smss.exe", "registry" and "memorycompression". It started without any previous changing.Have you got some information about this topic?Thanks

Http logs collector example not working

Hihope this is the right place to ask this questionWe were given a temp user to play around with the Cortex XDR and we are trying to insert some dummy data into it.I am trying to insert data using an Http logs collector, following this guideunfortunately, the example in the guide seems to be incorrect. I created a custom collector of HTTP type a...

Resolved! Differentiating mail from multi-tenant XDR

I am working with a multi-tenant XDR configuration and I would like to differentiate between the Alert Emails to ascertain from which tenant the Alert has been produced . For example: Tenant 1 and Tenant 2 (mssp). When I receive an email notification such as BIOC or LA Malware the content and subject does not provide me with any indication of so...

How can Cortex XDR Pro find the origin process from a DNS request if the process not uses DnsQueryEx RPC Call

Hi Community,Is somebody able to explain if Cortex XDR Pro is able to find the origin process if you have the DNS Query? A lot of windows internal process uses rpc calls to a svchhost.exe, which then makes the dns resolving, which is cortex xdr pro the source of a searched dns request. If i understand this articel right: https://stackoverflow.co...

fhu_omi by L1 Bithead
  • 5392 Views
  • 3 replies
  • 0 Likes

Resolved! Cortex Change managing server

Hi Team, I'm seeing the different tenant address in Cortex xdr agent console it is connecting to another management server,Could someone please help me to replace the correct managing server name, Because currently that agent is not reporting to Cortex console but I can take remote of the machine where agent is installed

XQL - Hunt for Kerberos Relay Up Activity

Just posting, if this is useful for someone who might be hunting for Kerberos Relay Up (Privilege Escalation on Windows System) Activity.The purpose of this hunt is to look for suspicious logon on windows system using Kerberos Auth Package where the source of logon is localhost IP and user account is Administrator SID.dataset = xdr_data | filter...

Resolved! XDR agent not triggering alerts in the managements console while blocking

Hi, I have a rather peculiar issue(?) with one of my agents.Said agent is working as intended, however it blocked a certain file form running under "Local Malware Analysis". which is fine, but I did not receive any alert nor incident in the management console.while the end user received a notification that a file has been blocked, I received no...

  • 2601 Posts
  • 98 Subscriptions
Top Solution Authors
Top Liked Authors