Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4332 Views
  • 0 replies
  • 3 Likes

Resolved! About Behavioral Threat Protection (BTP) rules

Hi Everyone:Does anyone know where I can find Behavioral Threat Protection (BTP) rules?For example, a behavioral threat is detected (rule: pp.epm_for_malware_behavior_j01)or Behavior threat detected (rule: bioc.pp.ransom_prevention_final)What do these two rules mean?Thank you Richard

Resolved! Cortex xdr 7.0 and 7.1 agent end of life

Hi All, We need to upgrade the cortex agent from version 7.1 to 7.3 via console. My concern is how can we exclude a certain range of endpoints (Suppose we have 5000 endpoints and we want to exclude 800 endpoints) from upgrading. I have created an endpoint group that we want to exclude. but not sure how to exclude. Can anyone please advise? Rega...

AsifSid by L2 Linker
  • 9030 Views
  • 7 replies
  • 0 Likes

Resolved! Duplicate endpoint

Hello, I regularly reinstall my endpoints. This creates duplicates for me and it's difficult to locate all the duplicates. Is there a query to see all endpoints as duplicates?

Besnard by L0 Member
  • 7463 Views
  • 4 replies
  • 1 Likes

Resolved! Cortex XDR/Data Lake

Hello. I can not see any logs in my Cortex Data Lake. Also when i go to Explorer app in Hub it is empty. Firewall Logs is also seem empty( I forward logs to Data Lake with Broker VM from Fortigate). Can anybody explain me this situation? NOTE: I have Cortex XDR Pro per Endpoint and Cortex XDR Pro per TB licenses. Thanks!

Resolved! Cortex XDR whitelisting

Hi, We have been asked to whitelist a specified folder in order to disable any kind of real-time checks and analysis made by Cortex XDR. So, we added the aforementioned folder in the allow lists of "Portable Executable and DLL Examination" and "Behavioral Threat Protection" sections in "Malware profile" configuration.With this kind of configurat...

MCereda by L0 Member
  • 14125 Views
  • 3 replies
  • 0 Likes

Resolved! wf_vericts json file verdict values?

Exported wf_verdicts.db from an endpoint to validate local verdicts. Is there any reference for return codes and their meanings? example:"value": {"verdict": 3,"lruData": {"lastUsed": "1613061210","index": "65945"

JoeDay by L0 Member
  • 3686 Views
  • 3 replies
  • 0 Likes

Cortex install fails on the Machines with Traps

the Cortex install fails on the systems which already has Traps (previous EPP) I have tried this command (below) which was recommended by Palo Alto, was working previously for few systems, but isn't the same nowmsiexec /i \\fps01\Users\rinesh.nanu.2\Cortex\Cortex_x64.msi CLEAN_AGGRESIVLY=1 /L*v \\fps01\Users\rinesh.nanu.2\Cortex\exc02\log.txt

Resolved! Default Landing Page & Incidents Filter

Is there a way to set the system (with cookies enabled, or not) to default to the Incidents Page when first loading? IOW instead of going to the default dashboard have it load the Investigations/Incidents section as default. Also, when going to to the Incidents page, can you set a default filter to load without having to select one? Right now yo...

News about CPATR-10685? This bug is disrupting production

Hello Everyone, Does anyone know where I find more information about this bug: CPATR-10685? We reported an issue where if the malware scan is running a dll cannot be loaded twice because Cortex XDR will block it and were given this bug number, but I cannot find it anywhere in the known or addressed issues. The fact that a dll is only allowed to ...

YAlhazmi_0-1615974821949.png
YAlhazmi_1-1615974867681.png
YAlhazmi by L1 Bithead
  • 3861 Views
  • 3 replies
  • 0 Likes

Cortex XDR - False positive - Cloud2Model Manager 1.005

hi,Some of the users of Cloud2Model are resporting that Cortex XDR is blocking the installer "Cloud2Model Manager 1.005 x64 setup.exe" with this Cortex XDR code: c0400055. This is a legitimate application and the installer is signed with a EV code certificate. You can check the instaler here:https://download.cloud2model.com/managerPlease check t...

eproca by L1 Bithead
  • 16199 Views
  • 11 replies
  • 0 Likes

Resolved! XDR agent is showing high memory consumption

Hello, We installed the agent on different devices. But we have noted that there are high levels of memory. In some devices, we see 180 MB. But in other, the memory is above 300 MB (especially VDI). Is this a normal situation? Or are there specific configurations that we need to change to improve this? We have reviewed the documentation and ther...

iscott by L2 Linker
  • 13301 Views
  • 2 replies
  • 0 Likes
  • 2593 Posts
  • 97 Subscriptions
Top Solution Authors