Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4356 Views
  • 0 replies
  • 3 Likes

Securing old web server IIS6

Hello, We are solving a case of an IIS6.1 vulnerability on an old Windows 2008 R2 SP1 system. Microsoft no longer has support for Windows update. The customer cannot migrate to the newer system yet.Would Cortex XDR be able to secure IIS v6.1 web server vulnerabilities? Thanks!

Fido by L0 Member
  • 3855 Views
  • 4 replies
  • 0 Likes

Resolved! Correct resolve types for XDR Incidents

Hi All, I tried to find this on PA Knowledge base but unsuccessful. Our team tries not to make exceptions/whitelisting unless absolutely needed. Therefore, I believe teaching Cortex XDR correctly on what is safe and what is not is crucial. For example when investigating successful logons from suspicious country (Low Sev Alert), if a user confir...

Java Deserialization Protection

Hello,I am looking to enable the "Java Deserialization Protection" in my exploit profile. I see the default is to leave it disabled. anyone else have this enabled?any advise or experience working with this?

P.Jacob by L3 Networker
  • 5365 Views
  • 3 replies
  • 1 Likes

Getting Multiple alerts about file "TwitchClient.exe"

I'm getting multiple alerts about the file "TwitchClient.exe" which is under below path C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.21.10043.0_x64__0a9344xs7nr4m\radeonsoftware\twitch\TwitchClient.exe Is this file is a legitimate file or do we need to worry about it.

Cortex XDR - Whitelist services in properway

Hi All 😄I'm new to Cortex XDR Hub and i'm trying to manage somes clients in the right way.I got this situation:There are some clients who had used IoBit - DriverBooster for the drivers installation on the machine.A lot of services about this application it's matched like Greyware or "Bad signature"Soo for first step i checked all the services w...

mgussoni by L0 Member
  • 5871 Views
  • 2 replies
  • 0 Likes

Resolved! macOS Network Filter limited to no more than one active network service on M1 Mac

Hi, I'm an enduser of Cortex XDR. Recently my workstation was migrated from an Intel MacBook Pro to a M1. During the migration process, both workstations were on macOS Monterey 12.3.1. I've discovered on the M1 that with the Cortex XDR network filter present in Network, I cannot have more than one network service active. Examples: wifi and ether...

Resolved! Query Network

Hello XDR Community! when the network (see screenshot) will be depprecated, will it be possible to get all the informations under network connections? I don't get the same results and not dst_host which would be very usefull. Here is my Query:Network [ action type = all AND remote ip = XXX.XXX.XXX.X ] AND Time [ event timestamp in last 24H befo...

RFeyertag_0-1649460837699.png
RFeyertag by L4 Transporter
  • 4700 Views
  • 4 replies
  • 0 Likes

Server Core

Is it possible to install Cortex on a Server 2019 core edition? There is no graphic interface but we'd like to have Cortex running on all our servers. Thanks!

Resolved! Expired Certificate in Cortex XDR documentation

Hi, Just wondering if there is any reason why we need to keep the expired certificate on system for Cortex XDR. https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/get-started-with-cortex-xdr-prevent/set-up-endpoint-protection/enable-access-to-cortex-xdr The ROOT CA for Global Sign is expired:SHA1 Fingerprint— 75 E0 AB B...

Resolved! Using XDR Host Insights and XQL to report of machines with specific software

Hello All I would like to use host insights to provide a list of each machine with a specific software installed.For example computer that have software containing 'docker' I can go to host insights, Applications, filter to include 'docker' and see the versions and numbers of assets. however you cannot export the lost of each asset here, just t...

Do Palo Alto plan to add endpoint DLP option to the Cortex XDR/Traps offering?

In many cases the firewall based DLP or Prisma Access cloud based DLP is good enough but in some cases like if the web site can't be decrypted or a local corporate site that does not go through the Prisma Access an endpoint DLP is great. So I have to ask if palo alto is looking at this option to add DLP to the Cortex XDR/Traps as an endpoin...

Resolved! Penetration testing for publicity

Hello! are we allowed as cortex xdr customers to penetrate the security suite through other researchers/analysts like TPSC https://thepcsecuritychannel.com/ ? They will also put a video on youtube. Thanks BR Rob

Cyber1985 by L3 Networker
  • 3593 Views
  • 4 replies
  • 0 Likes

Threat Intelligence Feed (IP-Adresses)

Hello! we have bought a DNS SEC product with a TI Feed (with bad IPs - about 900k). How can we integrate this into Cortex XDR? It is a textfile, which can be downloaded through a simple link. IP1IP2...We need a way to put this IP-Check somewhere on the agent, because our Firewall doesn't like that much IPs on the blacklist. When Cortex XDR can't...

Cyber1985 by L3 Networker
  • 2225 Views
  • 2 replies
  • 0 Likes
  • 2599 Posts
  • 98 Subscriptions
Top Solution Authors