Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 271 Views
  • 0 replies
  • 2 Likes

Resolved! Post detected by Wildfire

Hello dear community, 

what means Detected (Post Detected)? 

In our case, we see pdfpower.exe incidents popping up, the user says he didn't download anything to the incident time.

I think, the agent is scanning the OS, when there is allready a quaran

...

RFeyertag_0-1687468667966.png
RFeyertag by L4 Transporter
  • 7773 Views
  • 5 replies
  • 0 Likes

Resolved! Need help - BIOC / Script / XQL?

Hey everyone. I need some assistance in looking at this logically.

 

We have an identified PuP in our environment that is persistent. It creates a scheduled task and if you don't remove that, your PuP that you deleted will be back in no time.

 

Is th

...

Mac Cortex XDR Upgrade causing Device Freezing

Hello,

 

My organisation is currently running Cortex XDR 8.6.0 on Sequoia. We're finding that when performing upgrades of the application via the Console or by Jamf that the who device will freeze for 15+ seconds.

 

We're in an environment where we'r

...

Interpreting alerts on XDR

Hi, The alerts on XDR and very much rigid and not readable even to the support personnel, whenever I raise a case they keep checking with other teams teams and higher support levels to get details, for example how to interpret the below, it says susp

...

eXtended Threat Hunting (XTH) Module

Hi team,

Got a renewal quotation with new XTH module.

Heard eXtended Threat Hunting (XTH) Module is about query the raw data for threat hunting.

Still not so sure what is the new module is used for?

What is the use case to purchase this lic in additi

...

Query: All vulnerabilities under 29 days

I created this query to identify all vulnerabilities under 29 days: 

 

dataset = va_cves
| alter days = timestamp_diff(current_time(),publication_date ,"DAY")
| filter days > 0 and days < 30
|arrayexpand affected_hosts

Is there a way to tie in IP Address

...

Arcon Onboarding of Broker VM's

Hi Team,

We are planning to on-board the broker vm's to arcon for which we need the hostname and the user id of these broker vm's. Could you please assist how to get these details for the broker vm's to get it onboarded to arcon. These broker vm's are

...

Resolved! BTD - PROCEXP152.SYS - Vulnerable Driver Loaded

Cortex blocked driver PROCEXP152.SYS from being loaded (rule: sync.vulnerable_driver_by_original_name_loaded_procexp)
The thing it that this is a signed microsoft driver and it's kind of a known situation for many other vendors.

Links: Process Explorer

...

Panagiss by L1 Bithead
  • 9879 Views
  • 2 replies
  • 0 Likes

UNKNOWN USB DEVICE tdevflt.sys

Hi, i´ve a USB port problem.

I´ve already update all the lenovo drivers both automatically and manually and it didn't work. The PC keeps blocking me the USB ports.

When i was looking for the solution, we tried to disable the cortex agent and after a

...

Broker Link

Hi, I need a method to identify endpoints in my environment that are not communicating or linked the broker but Cortex is installed, noting that those machines do not have internet access.

 

Thanks,

  • 2152 Posts
  • 83 Subscriptions
Top Liked Authors