Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4322 Views
  • 0 replies
  • 3 Likes

Status Cortex XDR

Hello communityDo you know where can i see the percentaje uptime of CortexXDR service? I know about this link: Palo Alto Networks Cloud Services Status but it did not help me.

Cortex is not revoking non-persistent VDI license after user logout

Hi Community, We have one golden image and non-persistent VDIs are spawning from it. we installed traps in the golden image with VDI enabled=1. I can see the golden image install type is coming as a golden image, but the VDI generated from this has install type standard instead of VDI. I can see the vdi=0 as well in the VDI machine trapsd.log.L...

Resolved! Windows Server 2003 unable to check in to TMS

Hello everybody, I'm trying to connect an old Windows Server 2003 (service pack 2, 32 bits) to the traps management service. I know that I have to use an old version of the agent (I've installed 5.0.10), but the agent fails to check into the TMS. The problem is related to a certificate that the agent fails to validate. I installed all the requ...

grenzi by L3 Networker
  • 8658 Views
  • 9 replies
  • 0 Likes

Inconsistent XQL search results

When carrying out XQL search...."dataset = xdr_data | fields action_country | dedup action_country"I receive a set of results with different action_country values as expected.If I then take one of these values ie Switzerland and run "dataset = xdr_data | fields action_country | filter action_country = SWITZERLAND"I receive expected results.If i ...

Cortex is not revoking non-persistent VDI license.

Hi Community, We have one golden image and non-persistent VDIs are spawning from it. we installed traps in the golden image with VDI enabled=1. I can see the golden image install type is coming as a golden image, but the VDI generated from this has install type standard instead of VDI. I can see the vdi=0 as well in the VDI machine trapsd.log.L...

Resolved! Block especific Process and Folder/directory

Hello community,In our company we have implemented Cortex XDR with Pro per endpoint and pro per terabyte licenses.the incident response area asks me to verify the viability of applying the following preventive measures in cortex xdr1st. Block the execution of a specific process by its name without having the hash.2nd block writing and execution ...

XDR sometimes blocks the use of left mouse clicks on Windows Start Menu

We've deployed the Cortex XDR agent version 7.1.2 to 50-60 end-user machines so far. 2 users have reported the agent has stopped the use of left mouse clicks on the Windows Start Menu and Search Box. Right mouse clicks work fine. As soon as we removed the agent from those machines the Start Menu and Search Box started to work with left mouse cli...

Agent 7.2 dont comunicate with broker vm

I proceeded to install cortex XDR on a Kali, respecting the installation parameter chmod + x Kali.sh - --proxy-list "proxysrv: 8080,10.250.1.34: 8080" However, the client cannot contact the broker the error it is a timeout. my query is the following, is the proxy broker compatible with the linux agent? What more tests should I carry out to know ...

romansad by L1 Bithead
  • 7838 Views
  • 6 replies
  • 0 Likes

Investigating ABIOCS

I'm investigating the cause of ABIOC alerts. We've seen one particular alert that appears to be a false positive but I'd like to get some more information to be sure and to understand these alerts better: Name: Suspicious process accessed a site masquerading as Google Are there any resources that would be helpful to better understand these? In t...

DanBrook by L0 Member
  • 3281 Views
  • 2 replies
  • 0 Likes

Trying to create an exclusion for a process with a specific cmdlet (exploit)

For the past couple of days, we have received a low priority alert with the following params:Source: XDR AgentCategory: ExploitAction: Prevented (Blocked) In researching the alert in the alert table, I have determined that the action is tied with a homegrown powershell cmdlet. My conundrum is I want to create an exclusion for the specific power...

RNance by L0 Member
  • 5883 Views
  • 3 replies
  • 0 Likes
  • 2589 Posts
  • 95 Subscriptions
Top Solution Authors