Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4504 Views
  • 0 replies
  • 3 Likes

Server Core

Is it possible to install Cortex on a Server 2019 core edition? There is no graphic interface but we'd like to have Cortex running on all our servers. Thanks!

Resolved! Expired Certificate in Cortex XDR documentation

Hi, Just wondering if there is any reason why we need to keep the expired certificate on system for Cortex XDR. https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/get-started-with-cortex-xdr-prevent/set-up-endpoint-protection/enable-access-to-cortex-xdr The ROOT CA for Global Sign is expired:SHA1 Fingerprint— 75 E0 AB B...

Resolved! Using XDR Host Insights and XQL to report of machines with specific software

Hello All I would like to use host insights to provide a list of each machine with a specific software installed.For example computer that have software containing 'docker' I can go to host insights, Applications, filter to include 'docker' and see the versions and numbers of assets. however you cannot export the lost of each asset here, just t...

Do Palo Alto plan to add endpoint DLP option to the Cortex XDR/Traps offering?

In many cases the firewall based DLP or Prisma Access cloud based DLP is good enough but in some cases like if the web site can't be decrypted or a local corporate site that does not go through the Prisma Access an endpoint DLP is great. So I have to ask if palo alto is looking at this option to add DLP to the Cortex XDR/Traps as an endpoin...

Resolved! Penetration testing for publicity

Hello! are we allowed as cortex xdr customers to penetrate the security suite through other researchers/analysts like TPSC https://thepcsecuritychannel.com/ ? They will also put a video on youtube. Thanks BR Rob

Cyber1985 by L3 Networker
  • 3709 Views
  • 4 replies
  • 0 Likes

Threat Intelligence Feed (IP-Adresses)

Hello! we have bought a DNS SEC product with a TI Feed (with bad IPs - about 900k). How can we integrate this into Cortex XDR? It is a textfile, which can be downloaded through a simple link. IP1IP2...We need a way to put this IP-Check somewhere on the agent, because our Firewall doesn't like that much IPs on the blacklist. When Cortex XDR can't...

Cyber1985 by L3 Networker
  • 2291 Views
  • 2 replies
  • 0 Likes

Can recognize Signer but not signature

I have a security event, I clicked in and found that the CGO signature is unsigned, but when I create an alert exception, it recognizes the signer, why is that? The signature is not recognized, but the signer can be recognized

12.png
13.png
Grady by L2 Linker
  • 2412 Views
  • 1 replies
  • 0 Likes

Resolved! Admin password changes

I received an email yesterday saying the passwords for admin accounts will need to be updated before April14th.I just wanted to confirm that only admin passwords are being changed. Will there be any changes to integration API keys?

Resolved! Best Simulated (Fake) Malware To Use With Cortex XDR

Hi all,Do you all know what the best simulated malware is to use in testing out rules/responsiveness/etc on Cortex XDR and where to download these fake malware from. Ideally it'll be benign specially constructed so they trigger same alerts as actual malware. A dozen high-fives for tips, suggestions, participation, etc.

Cortex Subscription license doubt

We have deployed more than 800 agents in the network. Currently, we have a trial license but they will purchase the license the next month. If the actual license will come did we have to again reinstall the agents.

C:\ProgramData\Cyvera\Prevention folder piling up after installing cortex XDR

Hi Team, After installing cortex XDR, I can see C:\ProgramData\Cyvera\Prevention folder is getting filled up fast in one of the servers. There are a lot of activities on this server and Traps is catching some malicious activities often. This will definitely create logs, but i have below queries if anybody can help.is there any way to restrict th...

Resolved! XDR 3.2 Broker VM Kernel version

Hello ,We are using Cortex XDR Prevent 3.2 with 2 Broker VMs for Proxy access .I guess Broker VMs are Linux appliance . So is there any way to find the Linux kernel version which these VMs are running ?Thanks in advance for response

Balaraju by L2 Linker
  • 2972 Views
  • 2 replies
  • 0 Likes

XdrAgentCleaner Execution Monitoring

Is anyone monitoring XdrAgentCleaner execution? And if so i have a question, lets say when we run the XdrAgentCleaner, before the agent cleans all the Cortex traces, does it sends the EDR telemetry to cloud so in case if XdrAgentCleaner is used maliciously it can be tracked by creating detection rules of some sort?

  • 2635 Posts
  • 99 Subscriptions