Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4320 Views
  • 0 replies
  • 3 Likes

Cortex errors on laptop

Hi All, I have been notified that few of the users are receiving errors (attached) related to Cortex.I need to investigate this but not sure where to start and what to look for, Can anyone guide me here. RegardsAsif Siddiqui

AsifSid by L2 Linker
  • 2634 Views
  • 1 replies
  • 0 Likes

Cortex XDR: iexplorer.exe execution triggers the Memory Corruption Exploit Module

Hi, I am having this problem in a host managed by Cortex XDR , whenever I execute iexplorer.exe or outlook an xdr agent alarm is triggered indicating that it's a Memory Corruption Exploit. Except creating an Exploit profile and excluding this kind of alarm , is there any other solution , has anyone the same problem? Process blocked: C:\Program F...

Resolved! Cortex XDR - Operations for an offline agent (isolated from internet access) - Concerns regarding installation and updates.

Dear Palo Alto Community Members, I hope you will be able to help me out or point me in the correct direction. I'm struggling to find appropriate information about the operations for a cortex agent which will not be connected to the internet and will never be able to communicate with the cloud (Cortex XDR). In my customer scenario, the machine i...

Cortex XDR also impacting opening of files on the shares.

Hi Team, We have been notified that Cortex is taking up a lot of memory on Desktops and servers, is there any performance tweaks you can make? Cortex XDR also impacting opening of files on the shares, I need to understand what all things we can check if cortex is impacting the performance of the system where it is running? RegardsAsif Siddiqui

AsifSid by L2 Linker
  • 3806 Views
  • 1 replies
  • 0 Likes

Global Protect saml autentication and azure ad configuration?

Hi, I have configured gp with saml autentication; my azure ad connector is configured for hash pass synchronization.I noticed that gp always authenticates me regardless of whether the password has expired or not.there is no way to force me to change the password from the 365 screen? do i need to configure pass through autentication?Thank you

Device Control - Exception

Dear guru, Currently testing the flexibility of the Device Control Feature under XDR. Aim:Block all the mobile phone connecting to Endpoint except some VIPs. Gone thru the Admin manual, added a Device Config policy to block all Windows Portable Devices, apply a the Device Exception for the VIPs may be the way to do so. However, when configuring ...

Endpoint_DeviceControl_Exception.PNG

Resolved! Cortex XDR clean-up activity

Hi All, I have been assigned a task where i need to do cleanup in Cortex xdr, this is specifically for agent clean-up to determine how may more licenses we required.I need to understand what all things I should check and perform. RegardsAsif Siddiqui

AsifSid by L2 Linker
  • 5098 Views
  • 1 replies
  • 0 Likes

Resolved! Auto update XDR agent when new station connects.

Is it possible to automate the endpoint updates so any workstations reporting into Cortex will get upgraded to a minimum version ?Right now we have a query that can check for lower than minimum version and detected devices can be selected to be upgraded, but it's a manual process.(I tried to open a support case, but when choosing Endpoint Protec...

CHKlomp by L2 Linker
  • 7750 Views
  • 1 replies
  • 0 Likes

Auto Scan For External Devices

im looking to enable auto scans for all external devices connected to the endpoint (we use Cortex xdr) For example: If a USB drive gets plugging in it will get auto scanned by XDR. Cant seem to find the location of this setting Please advise,A

Resolved! Cortex XDR for Mac version 7.4.0

HiI am using a MAC with BigSur version 11.4 and Cortex XDR for Mac version 7.4.0Suddenly I am no loger able to debug in Xcode, since the debug server i killed by Cortex.Also when I debug from VSCode in C# I get a notification, but debugging does take place.So basically my Mac is so safe that it is unusable. How can I get solve this?Error message...

I Wants to create new user account in Cortex xdr

Hi All, We have a new requirement where we need to integrate Cortex xdr with IBM Qradar and for this integration I have a IBM guide where it ask to download and install cortex xdr app, which we did, however from Cortex side (in Console) there are few steps which we need to follow like creating a syslog server etc, If anyone has performed this in...

AsifSid by L2 Linker
  • 2946 Views
  • 1 replies
  • 0 Likes
  • 2585 Posts
  • 95 Subscriptions
Top Solution Authors