Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4396 Views
  • 0 replies
  • 3 Likes

Agent 7.2 dont comunicate with broker vm

I proceeded to install cortex XDR on a Kali, respecting the installation parameter chmod + x Kali.sh - --proxy-list "proxysrv: 8080,10.250.1.34: 8080" However, the client cannot contact the broker the error it is a timeout. my query is the following, is the proxy broker compatible with the linux agent? What more tests should I carry out to know ...

romansad by L1 Bithead
  • 8018 Views
  • 6 replies
  • 0 Likes

Investigating ABIOCS

I'm investigating the cause of ABIOC alerts. We've seen one particular alert that appears to be a false positive but I'd like to get some more information to be sure and to understand these alerts better: Name: Suspicious process accessed a site masquerading as Google Are there any resources that would be helpful to better understand these? In t...

DanBrook by L0 Member
  • 3345 Views
  • 2 replies
  • 0 Likes

Trying to create an exclusion for a process with a specific cmdlet (exploit)

For the past couple of days, we have received a low priority alert with the following params:Source: XDR AgentCategory: ExploitAction: Prevented (Blocked) In researching the alert in the alert table, I have determined that the action is tied with a homegrown powershell cmdlet. My conundrum is I want to create an exclusion for the specific power...

RNance by L0 Member
  • 5999 Views
  • 3 replies
  • 0 Likes

Backup software performance

One of our VMs seems to have its performance really impacted when backups run on a file server. I do not readily see guidance for suggestions on how I might adjust Cortex XDR Prevent's settings to improve things since there is a fair amount of data being read by the backup software. As usual the backup vendor's silly guidance is to not run AV ...

cortex xdr - submit false positive - shuttools 1.81

Palo Alto I am having a problem with your program mis classifing my tool suiteShut.Tools.1.81.docmas a false positive. Its a vba macro that has previously been clearing my Microsoft and utilises some MVP code. I depend on this to undertake my tasks and is currently being flagged as a false positive by cortex xdr. Previously traps did cause ma...

Quarntine Malicious file detected by scan

Hi all,When I initiate a scan to a machine a the action of malicious file is Detected (Scanned) but it is not getting quarantine although we enabled the quarantine malicious files in Behavioral Threat Protection.Anyone know the reason ?Thank you,

Resolved! Broker VM and SSL Certificates

Hello PAN Community, I am trying to import SSL certificates to Broker VM. However, when I try to import Private Key, it does not prompt me for the password. Does this mean I have to export the Private key without requirement for passphrase? Thanks.D

DKasabji by L2 Linker
  • 6659 Views
  • 2 replies
  • 0 Likes

Endpoint shown as 'Connection Lost' - cannot reach

I have a user (my boss) who is one of several endpoints with a status of 'Connection Lost'. I'm not actually able to ping him from the DNS server when he is plugged in to the network at work; the XDR portal reports two IP addresses which are probably from his domestic wifi.Running the msi to install isn't possible because tamper protection is en...

TimGowen by L1 Bithead
  • 26334 Views
  • 8 replies
  • 0 Likes
  • 2611 Posts
  • 98 Subscriptions
Top Solution Authors
Top Liked Authors