Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 1675 Views
  • 0 replies
  • 3 Likes

Resolved! XDR agent quota exceeded

We were monitoring the XDR Agent Audit logs and found out a lot of agents have this alert Quota Exceeded: "XDR agent quota exceeded on ******."

Can anyone explain this? 

Cortex XDR Connection method

Hi, While monitoring network traffic during our deployment, we noticed that all traffic between the endpoint and the XDR portal (<xdr-tenant>.xdr.<region>.paloaltonetworks.com) is one-directional (outbound).

 

We have private Linux servers in a separ

...

XQL query for critical commands

Hi everyone.
I'm trying to create an XQL query for a BIOC that will trigger an alert when specific commands are run.
I've tried the "visudo" and "sudo -l" commands on two servers. On one it detects both commands and on the other it only detects the "vi

...

Clean up Tags list

Hello All,

I want to clean up my tags list, because some of the old tags that we used are not needed any more.

We don't have active devices with tags that I want to remove.

Any idea from where i can do that?

 

Regards,

Vasil

Resolved! Windows 11 security features

We are in the process of testing/implementing Windows 11 OS on endpoints and noticed upgraded security features that are available to toggle on. Some of these protection features are already within the cortex polices. 

 

If we toggled these features

...

KamalKishore_0-1740437562031.png
KamalKishore_1-1740437571171.png

Anti-tampering Protection

Hello, 

I got incident with Anti-tampering protection which was blocked, i reviewed the alert by CMD C:\WINDOWS\system32\svchost.exe -k GPSvcGroup

it it false postive?
any ideas?

 

Cortex XDR 

Security Channel Subscription Errors

Team,

While trying to collect logs from windows, one channel that is consistently resulting in errors is security channel. Systems and Applications work just fine eliminating any possibility connectivity or authentication issues. It is the security c

...

Cortex XDR Query for USB/External Drive Usage

Hi Family 

Good morning.

I am trying to filter the timeframe when a user last connected a USB flash drive or external hard drive using a Cortex XDR query. However, the following query did not return the expected results:

 

 
dataset = xdr_data | f
...

Resolved! XQL chart editor

Hi. just i'm little stuck...

 

config timeframe = 1y
|dataset= incidents
|filter (status in (ENUM.RESOLVED_FALSE_POSITIVE,RESOLVED_AUTO_RESOLVE))
|fields creation_time ,status
|alter month = format_timestamp("%m",creation_time )
|sort asc month
|comp count

...

TNurmi_0-1740054064047.png
T.Nurmi by L1 Bithead
  • 912 Views
  • 1 replies
  • 0 Likes

Resolved! Post detected by Wildfire

Hello dear community, 

what means Detected (Post Detected)? 

In our case, we see pdfpower.exe incidents popping up, the user says he didn't download anything to the incident time.

I think, the agent is scanning the OS, when there is allready a quaran

...

RFeyertag_0-1687468667966.png
RFeyertag by L4 Transporter
  • 12419 Views
  • 9 replies
  • 0 Likes
  • 2463 Posts
  • 88 Subscriptions
Top Solution Authors