Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4320 Views
  • 0 replies
  • 3 Likes

Cortex XDR- Compromise Assessment

Hi, we recently moved to Cortex XDR, and I’m struggling to run a forensic script (such as AmCache) across 100 endpoints. I need to have all the results automatically combined into a single Excel sheet after the script finishes, similar to how Fidelis EDR handles it.

N.aloufi by L0 Member
  • 618 Views
  • 1 replies
  • 0 Likes

Requesting Cortex XDR Demo

How can I get a cloud demo for Cortex XDR? I’ve tried requesting one, but I haven’t received any email back from Paloalto. https://www.paloaltonetworks.com/cortex/request-demo Cortex XDR

AAlsaadi by L1 Bithead
  • 747 Views
  • 1 replies
  • 0 Likes

Resolved! Easier way to run cytool

Hello XDR experts, We got 300+ linux servers need to run cytool command with the password. is it possible to write a shell/python script with the password to do so? thanks a million SDG

Cortex Broker Mapper scans

We’re experiencing an issue with Cortex brokers related to the network mapper.When we run network scans using the "ICMP Echo" flag, the scan completes successfully and everything works as expected.However, when performing a "TCP SYN" scan on the following ports:80, 443, 22, 21, 25, 53, 23, 110, 123, 135, 137, 139, 143, 3389, 3306, 445, 1433, 161...

tlmarques by L4 Transporter
  • 1803 Views
  • 4 replies
  • 1 Likes

How can I see the device control violations logs from XQL?

Good afternoon, Is there a way to see the logs that are generated in Device control Violations? I know that using preset = device_control in XQL we can see devices but this preset does not give me all the data that appears in the Violations section... I need to see all the fields like these that appear: How can I obtain the information abou...

Rolando_Pena_0-1720811062737.png

Resolved! Query to see user that launched an EXE and how many times

I've been trying so many different queries and cant seem to make one that shows me what users launched an EXE and when or how many times as a count.As an example to make it easy: Search for everyone that executed winword.exe and show me when they did it. Or search of everyone that executed winword.exe and count of times in X rangeIf anyone has a...

J.Suter by L2 Linker
  • 1502 Views
  • 2 replies
  • 0 Likes

Resolved! In Cortex XDR, if the Cloud Identity Engine Azure Sync fails and then reconnects automatically without any action,

Hi Team, We are currently using the Cortex XDR Pro Per Endpoint license and have enabled the Cloud Identity Engine feature. We observed that the Azure directory synchronization within the Cloud Identity Engine failed temporarily but reconnected successfully without any manual intervention. why the sync fail and automatically connect again withou...

BTP Exception not working for ps1 script

Hi Team - I've created a Legacy Agent Exception Rule to prevent the Behavioral Threat Protection component from blocking a specific (and legitimate) .ps1 file on my network (within a specific user profile), but Cortex keeps blocking the script. The command line in the alert is: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "-file"...

Get results before and after 10 seconds of creation_time field

I need a query which will give me results 10seconds before and 10seconds after the alert creation_time field for investigation from a hostname. So i need to add 10seconds to the alert creation_time field and subtract 10seconds from the creation_time field. Please also add the timezone of GMT +2 For example if the the alert creation time is May 1...

rkumawat by L0 Member
  • 707 Views
  • 1 replies
  • 0 Likes

Change alert (not incident) severity for future same alerts

The severity of "Administrative Hash Exception" alerts (not incidents) is low, and since they are not created as incidents, I want to change the severity of these alerts to medium so that they are created as incidents next time. When I go to Incident Response > Automation > Add Automation Rule, I can't create a rule for these alerts becaus...

Aristooo by L2 Linker
  • 1370 Views
  • 1 replies
  • 0 Likes
  • 2585 Posts
  • 95 Subscriptions
Top Solution Authors