Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4494 Views
  • 0 replies
  • 3 Likes

XDR Agent Quota Exceeded

Hello, We receive numerous alerts of "XDR agent quota exceeded on ****" I understand this means that the default storage is being exceeded but what exactly does that entail? 1. Are the old logs not being overwritten in time causing the alert to set off since the space has been exceeded? is it actually going over the default space or is ther...

Resolved! Not seeing Cortex MCP Server Download

Hi all the Cortex MCP Server download under Settings → Configurations shows on commercial tenants but is missing entirely on our FedRAMP / Federal tenant (not a permissions issue). Is it on the roadmap for Federal environments, and is there an expected timeline for rollout? Thanks!

Resolved! Cortex XDR agent protection after 90 days of inactive

Hello Everyone. I need your opinion to this topic. What will happen to the agent protection for the endpoint after 3 months of inactive. Correct me if im wrong. Cortex XDR agent will delete permanently from management console and database after default deletion which is 90 days. if i enable all the module in day 1 for an endpoint, then af...

Resolved! Cortex XDR and Microsoft Defender Coexistence and Performance

Hello Cortex XDR Community,We recently were asked to have official guidance regarding the coexistence of Cortex XDR Agent and Microsoft Defender on Windows endpoints. My questions to the community and experts is: - Is the coexistence of Cortex XDR and Microsoft Defender Antivirus officially supported? - Is the coexistence of Cortex XDR and Micr...

DLP (DataPatrol) signed DLL injection into Word blocked by agent — permanent exception?

Our DLP watermarks documents by injecting a signed DLL into WINWORD.EXE on print. The Cortex agent blocks the injection — page prints with no watermark, DLL never loads. Works fine with the agent removed. Persists in Report mode, generates no alert/prevention event. Tried a Disable Prevention rule (signer + thumbprint, all modules, global) — no ...

Resolved! Protection Mode for Linux Modules

When configuring Reverse Shell Protection and Malicious Child Process Protection there's an option to configure the protection mode. Default is "normal" but we could choose "aggressive" too. There's no documentation. Does anyone know the difference of protection modes for these Linux modules? Is it the same as in the ransomware protection modu...

micomi_0-1782802979178.png
micomi by L3 Networker
  • 260 Views
  • 1 replies
  • 0 Likes

Anyone else having XDR communication problems?

Starting later in the day on June 24, we started seeing endpoints show 'No connection to server' when opening the Cortex console on the endpoint. Endpoint tasks like collect firewall logs, pause protection and live terminal all fail. Some systems shows that they ARE connected to our tenant but trying to live terminal into them fails.

Any specific post-installation procedure / configuration required to make sure the protection running on Mac without affecting performance ?

Dear All, Having a few MacOS devices (iMac, MacBook Pro) installed with Cortex XDR agent v9.2.0 for piloting (procedure follow through https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/9.2/Cortex-XDR-Agent-Administrator-Guide/Install-the-Cortex-XDR-Agent-Manually) They are running on monitoring (without blocking on "malware profile" and ...

Cortex XDR and Sandboxie

Hello, We have installed Cortex XDR on a VM that also runs a sandbox tool (Sandboxie). As long as Cortex XDR is enabled, processes cannot be started within the sandbox (e.g., msedge.exe, cmd.exe, explorer.exe). It only works if I create a "Disable Injection and Prevention" rule for these processes. How can I resolve this permanently? I suspect...

M.Wempen by L1 Bithead
  • 303 Views
  • 2 replies
  • 0 Likes

Resolved! XDR agent disconnected after automatic upgrade

After automatic upgrade is performed an endpoint now is disconnected with this message: XDR Agent failed to upgrade from version 9.1.0.20483 to version 9.2.0.120 on 79433PC with error: The content package was faulty or could not be downloaded. Is there a way to reconnect it to XDR console?

Operational Exception without Case

We are currently facing an issue with a Windows service. This service only functions properly after we add a specific executable (.exe) to the Operational Agent Exceptions . We haven’t seen any corresponding case or alert in the console, meaning Cortex XDR is not actively blocking anything. This raises the following questions: 1) Wildcards in Op...

M.Wempen by L1 Bithead
  • 410 Views
  • 1 replies
  • 0 Likes

Partialy protected

Hello everyone, I'm having issues with my Cortex XDR agent. The operational status is partially protected, with the following details:1. The OS I'm using is Ubuntu 24.04.02. I'm using the latest agent installer, version 9.2.0.1193. The operational status details generally state that the Linux kernel cannot be loaded. Is there a solution I can tr...

Cortex XDR Device Control Violation Alerts

Hi All, We enabled device configurations to block external devices connecting to endpoints in the organization and its work fine. In the Cortex XDR console, I can see the device control violations. We want to create alerts to detect the Device Control Violation based on a BIOC rule, as this is the only available option. I tried several...

Suspicious executable detected Microsoft Store Purchase App

Hello everyone, Has anyone seen this process appear in Cortex XDR? C:\Program Files\WindowsApps\Microsoft.StorePurchaseApp_22603.1401.4.0_x64__8wekyb3d8bbwe\StoreExperienceHost.exe It’s showing up on an endpoint, but Cortex XDR isn’t providing any additional details, alerts, or related events. Before I dismiss it, I want to confirm whether thi...

  • 2632 Posts
  • 99 Subscriptions