Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4322 Views
  • 0 replies
  • 3 Likes

Resolved! Extend Ransomware Protection to SMB Shares

I noticed that my tenant space has a new option in the Windows Malware Profile under Ransomware Protection that is named "Extend Ransomware Protection to SMB Shares". I don't believe this setting was available prior tot he 7.2 release that I read about today. I do not see anything in the release notes about this new setting/feature for 7.2 and...

Windows Defender does not disable after Cortex XDR v7.1.1 install

Hello, hope you are all doing well and staying safe. Traps v6.1.0 was installed on a server and Windows Defender never auto disabled causing Antimalware Service to run alongside Traps. I uninstalled Traps and replaced it with the new Cortex XDR v7.1.1, but still Windows Defender will not disable. For the majority of our systems Windows Defender ...

oburgos by L0 Member
  • 11153 Views
  • 2 replies
  • 0 Likes

XDR agent based firewall for locking down communication between DC's&SCCM

Hello everyone, We are looking to implement agent based firewall rules to lock down the communication between DC's and SCCM servers we have 20+ of each and I am wondering what is the most feasible way of doing that? User Guide has pretty much no guidance on anything FW related. Any suggestions would be appreciated.

initial profiling?

when you first install the Cortex XDR agent on a new server (and reboot if on Windows), is it immediately 'active' and blocking suspicious processes? I was told that it ran in 'passive' mode for 30-days as it built a profile of "normal" activity for that agent. I ask because we are starting to use immutable servers which are recreated from-scrat...

Signature Weak hash

Good day! community, I have a question, what treatment is given to executables that are signed as weak hash?I understand that cortex XDR will block its execution.Can it be excepted considering that it is a utility software?The hash is unaltered and WF's verdict is benign.What things should I verify or take into account as best practices to exped...

Change in the way URL Filtering alerts are presented in Cortex XDR?

Hello, beginning on or about 20 July, began to see MANY more Incidents created in Cortex XDR that looked similar to this:Incident Description: 'Threat ID #' generated by PAN NGFW detected on host <hostName> involving xyz\UserName(note, there is NOTHING after the "#" sign)Incident Sources: PAN NGFW When looking at the Alert that caused this...

Resolved! Vulnerability Assessment

Hi experts, Cortex now has the ability to report vulnerabilities on endpoints, currently limited to Linux endpoints. Does anyone know if this is going to be extended to Windows and other endpoint types? Thanks Darren

BizBo by L2 Linker
  • 3791 Views
  • 1 replies
  • 0 Likes

Resolved! Cortex error message

I keep getting a popup message from Cortex saying "Cortex needs to access your entire harddrive."Why is this message coming up and how do I get rid of it?I've tried reinstalling Cortex, updating the Mac OS, restarting my computer, and yet it keeps coming up on both of my Macs.Thanks for any help!Leona

Resolved! Using Hash View, but no Incidents are shown related when they should

Hello LIVEcommunity, I am wondering if anyone else is using Hash View in Cortex XDR and finding that even if a Key Artifacts of a Incident lists a hash, when you view that detail in Hash View (right click on the artifact, bring up the Hash View screen) the area where one might think there would reflect a "Related Incident" is blank?I have opened...

KRisselada_0-1595012463964.png
KRisselada_1-1595012581537.png

Cortex XDR Incidents new field

Hi all, This is my first post here.I had this idea/suggestion that a new field should be added on incidents page. When we deal with multiple incidents, a necessary field will be needed for quicker decision making for an analyst.So I wanted to suggest for field called "status" wherein the action taken on the consisted alerts is summarized.As the ...

What is an agent protection password?

I use MacOs and Cortex XDR, and I wanna uninstall the Cortex XDR.Cortex XDR Uninstaller.app said a following sentence:[ Enter agent protection password ( set by the administrator ) ] I didn't set the agent protection password.How can I uninstall the Cortex XDR??? MacOs Catalina 10.15.5Cortex XDR Version 7.1.1 Please help me.

nnEiji by L0 Member
  • 4512 Views
  • 2 replies
  • 0 Likes

Resolved! Cortex XDR Pro - Latest Agent 7.1.2 (Release Notes)

Hello, I have just downloaded and installed on 10 x machines for testing Cortex XDR Pro agent version 7.1.2 Been "hunting" about Paloalto portals for release notes and found nothing as yet relating to this latest agent version, have i missed them? Can someone please point me in the correct direction, thanks? Kind regards,Graeme

  • 2589 Posts
  • 95 Subscriptions
Top Solution Authors