Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 1475 Views
  • 0 replies
  • 3 Likes

Unable to retrive downloaded exe's

Hello everyone,

 

I was trying to check all the downloaded exe's via firewall on all the endpoints in past 24hrs. I tried retrieving all downloaded exe's in downloads folder with the help of this query below. 

dataset = xdr_data
| filter event_type =

...

XDR & Java installs

With the upcoming Oracle Java license changes, I'm looking into using XQL to report on existing installs, and potentially a process based BIOC to block new installs which would incur a licensing fee. 

Anyone familiar with Java know how to differentiat

...

SearchHost.exe

Hello Everyone,

 

I am new to Cortex XDR. I wanted to ask what is searchHost.exe? and if it is safe when it generates alarm (level Medium) in Cortex XDR? If not then any recommendations?

 

Thanks

USB protection exeption for ClickShare usb Device

Hello everybody,

 

if we block USB Drives/Windows drives our ClickShare (USB Screen Share Dongle) devices also get blocked.

But they don´t appear in the "Device Control Violations" list so we can´t exclude them from blocking. 

We tried to exlude the

...

D.Meyer by L1 Bithead
  • 2789 Views
  • 8 replies
  • 0 Likes

Resolved! Basic questions to host firewall

Hello dear community, 

 

what is the correct setting for disabling the management of host firewall through Cortex XDR? Why do I wan't that? Because I need to get the windows firewall running through GPOs. Host firewall from PA Cortex is not suitable

...

RFeyertag_0-1735955355407.png
RFeyertag by L4 Transporter
  • 1136 Views
  • 2 replies
  • 0 Likes

Directories CIEE x Cortex

dear, I have two directories in the cie, but in the cortex in the preset function it only brings the old one, not the newer one. How can I do it in Cortex so that it only brings information from the new directory?

Impossible uninstall Cortex XDR

Hello,

 

Because of my previous work, I had to install Cortex XDR to work remotely from home and access to the VPN.

Now that I'm no longer working for them, I would like to uninstall Cortex XDR from my laptop (MacBook Pro M2) but it is impossible. I

...

Rixals by L2 Linker
  • 6118 Views
  • 25 replies
  • 0 Likes
  • 2441 Posts
  • 88 Subscriptions
Top Solution Authors
Top Liked Authors