Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4397 Views
  • 0 replies
  • 3 Likes

Cortex Broker Mapper scans

We’re experiencing an issue with Cortex brokers related to the network mapper.When we run network scans using the "ICMP Echo" flag, the scan completes successfully and everything works as expected.However, when performing a "TCP SYN" scan on the following ports:80, 443, 22, 21, 25, 53, 23, 110, 123, 135, 137, 139, 143, 3389, 3306, 445, 1433, 161...

tlmarques by L4 Transporter
  • 1950 Views
  • 4 replies
  • 1 Likes

How can I see the device control violations logs from XQL?

Good afternoon, Is there a way to see the logs that are generated in Device control Violations? I know that using preset = device_control in XQL we can see devices but this preset does not give me all the data that appears in the Violations section... I need to see all the fields like these that appear: How can I obtain the information abou...

Rolando_Pena_0-1720811062737.png

Resolved! Query to see user that launched an EXE and how many times

I've been trying so many different queries and cant seem to make one that shows me what users launched an EXE and when or how many times as a count.As an example to make it easy: Search for everyone that executed winword.exe and show me when they did it. Or search of everyone that executed winword.exe and count of times in X rangeIf anyone has a...

J.Suter by L2 Linker
  • 1676 Views
  • 2 replies
  • 0 Likes

Resolved! In Cortex XDR, if the Cloud Identity Engine Azure Sync fails and then reconnects automatically without any action,

Hi Team, We are currently using the Cortex XDR Pro Per Endpoint license and have enabled the Cloud Identity Engine feature. We observed that the Azure directory synchronization within the Cloud Identity Engine failed temporarily but reconnected successfully without any manual intervention. why the sync fail and automatically connect again withou...

BTP Exception not working for ps1 script

Hi Team - I've created a Legacy Agent Exception Rule to prevent the Behavioral Threat Protection component from blocking a specific (and legitimate) .ps1 file on my network (within a specific user profile), but Cortex keeps blocking the script. The command line in the alert is: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "-file"...

Get results before and after 10 seconds of creation_time field

I need a query which will give me results 10seconds before and 10seconds after the alert creation_time field for investigation from a hostname. So i need to add 10seconds to the alert creation_time field and subtract 10seconds from the creation_time field. Please also add the timezone of GMT +2 For example if the the alert creation time is May 1...

rkumawat by L0 Member
  • 768 Views
  • 1 replies
  • 0 Likes

Change alert (not incident) severity for future same alerts

The severity of "Administrative Hash Exception" alerts (not incidents) is low, and since they are not created as incidents, I want to change the severity of these alerts to medium so that they are created as incidents next time. When I go to Incident Response > Automation > Add Automation Rule, I can't create a rule for these alerts becaus...

Aristooo by L2 Linker
  • 1613 Views
  • 1 replies
  • 0 Likes

Resolved! Palo Alto Cortex Broker Virtual Machine (Broker VM) security understanding

Following my company's compliance guidelines, we are looking for some confirmations about the Palo Alto Cortex Broker Virtual Machine (Broker VM). Could you, please, confirm that we have correct understanding on how the product works?1- It is not possible do an integration with an external authorization/authentication mechanism in Broker VM itse...

M.Sylos by L0 Member
  • 1357 Views
  • 1 replies
  • 0 Likes

RedHat 8/9 XDR client count limited

As I have added clients to my XDR Linux group I have seen a situation where I hit a limit on client count (under 20 BTW). After I have them all added there will be 2 or 3 missing. If I restart the process on a missing client, that one immediately appears, but one of the previous ones drops off. If I restart the process on that one the other one ...

Resolved! [Cortex XDR] Are there any How-To video recordered about Windows Event Collector applet for the broker VM?

Dear, Following the acquisition of the Pro license for GB to collect Windows logs from domain controllers, I saw documentation regarding the configuration of the Windows Event Collector applet from the Broker VM. However, I was wondering if there were any How-To videos as in the case of configuring the Syslog Applet. Do you guys know if there...

F.Ronchi by L1 Bithead
  • 1163 Views
  • 1 replies
  • 1 Likes

XDR Analytics Data source

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Analytics-Alert-Reference-by-data-source/BitLocker-key-retrieval https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Analytics-Alert-Reference-by-data-source/Exchange-mailbox-audit-bypass In the Analytics Alert reference guide- there is a reference to "AzureAD Audit Lo...

  • 2610 Posts
  • 98 Subscriptions
Top Solution Authors
Top Liked Authors