Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4358 Views
  • 0 replies
  • 3 Likes

Recent Change - creation of Threat ID #8002 Alerts in Cortex

Hello all, Beginning on or around 14/15 December, I began to notice we were commonly generating the following Alerts in Cortex:Alert name: Threat ID #8002Description: Scan DetectionAlert Source: PAN NGFWCategory: Scan Detected via Zone Protection ProfileThis is occurring on two different customers that have entirely different IT teams, but do bo...

KRisselada_0-1609434433229.png

Resolved! Feature Request: Ability to add a 'Comment' when Bulk Uploading IOC Rules in XDR

When adding IOC's to XDR, adding a comment is a useful way to keep track of where the IOC originated from. When an alert is triggered from that IOC, the analyst can review the IOC rule and read the comment for context. When 'bulk' uploading, using a file for example, there is no comment field. Is it possible to add the ability to make a comment...

AlCurran by L0 Member
  • 5872 Views
  • 2 replies
  • 0 Likes

The Cortex XDR version upgrade on my computer is not progressing from "In progress".

The Cortex XDR version upgrade on my computer is not progressing from "In progress".When grouping and upgrading some agent has stuck on "In Progress" situation, we cannot even cancel and stop it.Even rebooting the computer and then upgrading again does not work.Could you please advise how we can solve this issue?Thank You

mkakara by L0 Member
  • 6016 Views
  • 1 replies
  • 0 Likes

Cortex XDR Alert Dump File Analysis

Is there a way we can analysis the dump file when a behavior based alert is generated for an incident? We would like to analysis the process dump file with volatility for windows 10 machines.Thanks for the help in advance.

App-ID for endpoint-based BIOC rules

Currently, BIOC rules can be created for "NETWORK" (endpoint-based) or "NETWORK CONNECTIONS" (NGFW-based) but only the latter supports the usage of App-ID and VPN infrastructure isn't always in place or available. Are there any plans to add this?

2020 ∕ 09 ∕ 22 16꞉01꞉10 - Rule_Builder_-_Cortex_XDR_-_Google_Chrome.png
2020 ∕ 09 ∕ 22 16꞉01꞉38 - Rule_Builder_-_Cortex_XDR_-_Google_Chrome.png
2020 ∕ 09 ∕ 22 16꞉02꞉07 - Rule_Builder_-_Cortex_XDR_-_Google_Chrome.png

Feature Request – Add ability to capture memory dump

During a recent investigation our team came across a situation where we needed to take a forensic image of a device on our network. Prior to taking the image, we had hoped to utilize Live Terminal in order to remotely capture a memory dump to get a head start on our investigation. Unfortunately, we ran into several limitations including the fil...

GoToMeeting Whitelist

Does anyone know how to whitelist the GoToMeeting download? It is an EXE but the client agent blocks it. When I attempt to whitelist it, EVERY SINGLE download is a different hash value making it impossible to whitelist. Thanks for any suggestions.

FIltering for Content Version

Palo recently issued a security bulletin where we are protected if we have Content Update 150. I was trying to add a filter for "< 150-39463" to only see those endpoints that might not have checked in for a bit. The 7.1 documentation does not show a less than operator. Is there a way to do this other than adding multiple != filters for the...

Work with an email attachment

Hello community, I'm facing some problems in order to work with the attachment of potential phishing cases. The phishing button that we have configured sends the original email as an attachment without format. Which is making XSOAR read it like that: I've coded an automation that extracts everything needed from an email. In order to work I've te...

Sergio_Gonzalez_0-1607505981146.png
Sergio_Gonzalez_1-1607506152397.png

Bitlocker recovery keys not present

Hello,I wanted to check if someone can shed some light on this issue I had. During a Cortex XDR PoC, the end user activated the Disk encryption policy on a couple of workstations without confirming the pre-requisities so these workstations encrypted the HDD (C:) and after the first reboot started asking for the bitlocker recovery key. Now, the i...

Resolved! Accessing Files While Scanning

Hello, this might be a dumb question but I'm trying to find any documentation that might back it up. Basically, when conducting a system scan some apps can't be executed because they try to access certain .dll files which are being used or are open by Cortex XDR. I just want to make sure this is expected behavior and if there's any workaround. T...

  • 2599 Posts
  • 98 Subscriptions
Top Solution Authors