Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4392 Views
  • 0 replies
  • 3 Likes

Cortex XDR Agent offline notification

Hello Team, I would like to be notified by email when an XDR Agent goes offline. However, I could not find a function to notify the agent status.Do you know of any documentation that explains how to configure the agent status notification function? Regards,Yusuke Narita

Cortex XDR email data integration

Hi, i have integrated email data from Microsoft Graph API to Cortex Collections Integration -> M365, but still there are no phishing emails or suspicious emails being reported as incidents in Cortex. Could you let me know what should be done inorder to trigger such alerts and incidents in Cortex?

Cortex XDR API to get a full CVE list

We are working on an automation task that would like to download the CVE full list under "Vulnerability Assessment" of "Assets" from Cortex XDR menu pane. We would like to try API to download the contents and put it to CSV file format so that we can further processing our automation task. Please kindly advise if this can be achieved and what A...

Resolved! Kubernete agent change managin server

hello, we need to move all agents from a tenant A to a tenant B. for windows or linux we will use the command action endpoint control to change managin server on the tenant A. but how can we migrate Kubernete agent ? Regards, D.L

XQL help AD

Hi everyone,Anyone know how to query what types of AD queries users run?I want to (1) find users/computers doing AD enumeration and (2) see what kind of enumeration they ran.

tlmarques by L4 Transporter
  • 547 Views
  • 1 replies
  • 0 Likes

Cortex XDR: Removal on MacOS

Any resources on command-line/automated Cortex XDR removal (with key) for MacOS clients? We're a MSP/MSSP and have requirement often to bulk remove XDR when (e.g.) offboarding clients or during M&A activities, etc. I'd open a case at support but since *my* organization has not Cortex assets, I don't get that option. Does anybody have any r...

J.Winks by L1 Bithead
  • 583 Views
  • 1 replies
  • 0 Likes

Request for File Path Information in Cortex XDR Vulnerability Assessment Data

I'm using the XDR API to retrieve vulnerability assessment data (specifically the va_cves and va_endpoints datasets) provided by Host Insights. I would like to know if the API—or any other Cortex API—can provide the file path information associated with each vulnerability on an endpoint. Specifically Is there an endpoint in any of the Cortex ...

False Positive Issue - Multiple Windows System Processes Flagged by Cortex XDR

Hello everyone, I'm experiencing ongoing false positive alerts with Cortex XDR that are affecting multiple endpoints in our environment. I'm seeking guidance on how to properly address this issue. Environment Information: Cortex XDR Agent Version: 8.6.0.3704 Operating System: Windows 10 64-bit Issue Scope: All endpoints in the environment Prob...

2025-08-07_150647.jpg
2025-08-07_150548.jpg
2025-08-07_150235.jpg

Resolved! Vulnerability Management Cortex XDR (first detection date/time)

Hello, I want to make some reporting and dashboard with the data provided from the agent vulnerabilty Scan. I would like to obtain the following informations: How long has a CVE been present on a machine? How much time elapses between the appearance of a CVE and its disappearance (Hope is due to patching)on a machine? I find nothing in the tem...

MathB12 by L0 Member
  • 2059 Views
  • 3 replies
  • 1 Likes
  • 2611 Posts
  • 98 Subscriptions
Top Solution Authors
Top Liked Authors