Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4319 Views
  • 0 replies
  • 3 Likes

Cortex XDR Prevent Did Not Detect ncat

Hello I am new to Cortex XDR. I tried ncat on a PC with Cortex XDR Prevent (with Windows Defender) and it did not detect or stop the connection from Kali a PC. Windows Defender showed a warning and once I allowed it I was able to connect on ncat from Kali. Is Cortex XDR Prevent supposed to stop ncat or at least give me an email alert about the c...

Cortex XDR folder exclusion

Hello,does anyone know if it is possible to exclude an entire folder on a Windows machine from Cortex XDR scan in order to launch executable files without being blocked and having to add the file hash to the whitelist ?

Resolved! Force policy check in Cortex XDR

Hi, Is there any way to force a policy check on an endpoint? I have created a new Policy Rule and assigned a new set of Policy Profiles to it. I then assigned specific endpoints to this Policy Rule and the rule is #1 in the policy order tab. The problem I am facing is that the targeted computers do not seem to receive the new policy. YES, the r...

Cortex XDR Alerts - Slack Integration

Is there any way to include the hostname for alerts received in Slack? They are very valuable to receive on the phone late at night, but would be even better if we had a bit more information: hostname, domain, something that indicates this is a test box... 🙂Any takers? Is there something we need to tweak, or is this a feature request?Examples:A...

Exceptions "Child process"

Hello!! How are you? i need confirm an action when add exception for child process, i have several alerts for "WmiPrvSe.exe Rare Child Process" that are false positive, and im considering add to whitelist in the profile associated. For create it i need add parent process, child process and child process command, I need confirm if this works as...

Julitro_0-1598461562310.png
Julitro by L0 Member
  • 3309 Views
  • 1 replies
  • 0 Likes

CISCO ASA Firewall connection to Cortex XDR

Hi, We have an environment where by we have CISCO ASA Firewalls, our Client Base would communicate with a Proxy Server and then this would pass the details onto the Firewall and the ASA Firewalls would then communicate with Cortex XDR. As Cortex XDR requirements are to use FQDN instead of IP, has anybody had any experience of using CISCO ASA's w...

Resolved! Difference between exclusion and add to allow list Cortex XDR

good day community,I have an incident due to the execution of an excel file that contains macros.According to the verdict and its hash the file is not a threat.My question is the following which is the most suitable method to allow the execution of said file?In the incident analysis window, right click on the allow list process or generate an ex...

Resolved! Extend Ransomware Protection to SMB Shares

I noticed that my tenant space has a new option in the Windows Malware Profile under Ransomware Protection that is named "Extend Ransomware Protection to SMB Shares". I don't believe this setting was available prior tot he 7.2 release that I read about today. I do not see anything in the release notes about this new setting/feature for 7.2 and...

Windows Defender does not disable after Cortex XDR v7.1.1 install

Hello, hope you are all doing well and staying safe. Traps v6.1.0 was installed on a server and Windows Defender never auto disabled causing Antimalware Service to run alongside Traps. I uninstalled Traps and replaced it with the new Cortex XDR v7.1.1, but still Windows Defender will not disable. For the majority of our systems Windows Defender ...

oburgos by L0 Member
  • 11134 Views
  • 2 replies
  • 0 Likes

XDR agent based firewall for locking down communication between DC's&SCCM

Hello everyone, We are looking to implement agent based firewall rules to lock down the communication between DC's and SCCM servers we have 20+ of each and I am wondering what is the most feasible way of doing that? User Guide has pretty much no guidance on anything FW related. Any suggestions would be appreciated.

initial profiling?

when you first install the Cortex XDR agent on a new server (and reboot if on Windows), is it immediately 'active' and blocking suspicious processes? I was told that it ran in 'passive' mode for 30-days as it built a profile of "normal" activity for that agent. I ask because we are starting to use immutable servers which are recreated from-scrat...

Signature Weak hash

Good day! community, I have a question, what treatment is given to executables that are signed as weak hash?I understand that cortex XDR will block its execution.Can it be excepted considering that it is a utility software?The hash is unaltered and WF's verdict is benign.What things should I verify or take into account as best practices to exped...

  • 2582 Posts
  • 95 Subscriptions
Top Solution Authors