Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 748 Views
  • 0 replies
  • 2 Likes

Resolved! XQL Query Help

I am trying to create a rule for the case of creating a new user in the admin role. Where's my mistake?
I am grateful for your help.

dataset = xdr_data 
| filter action_evtlog_event_id = 4720

| alter Direct_Role = arrayindex(regextract(action_evtlog_me

...

Resolved! An endpoint with the Cortex XDR installation intermittently creates a huge file and writes to the hard drive at C:\Windows\System32\PaloNull

Dear Live Community Members,

 

One of my customers noticed that some endpoints with the Cortex XDR installation sometimes creates a huge file that grows in size with time.

On several VMs equipped with the Cortex Agent (version 7.7.1, but we also noti

...

PalNull.png
PaloNull_1.PNG

Resolved! create BIOC rules via Cortex XDR API

Hi community,
I'd like to enquire whether Cortex XDR can create BIOC rules via Cortex XDR API.
I could not find any description about creating BIOC rules on the following Cortex-XDR-API-Reference.

 

Cortex XDR API Overview | Cortex XDR (stoplight.io)

Resolved! block vulnerable applications from running

Hi community,

 

I am attempting with restricting the execution of vulnerable applications.

 

Is it possible to block a specific application version using BIOC associated with restriction profile?
(Or if there's another easy way to do this please let m

...

Resolved! XDR Agent version naming convention

Hi all,

 

I am a bit confused with the new Agent version numbers. So to be sure:

 

Taking the naming convention into account, isn't the XDR Agent version 8.5.0.624. higher and newer then version 8.5.0.3639?

 

8.5.0.3639 is recently released to suppor

...

AbdBgc by L2 Linker
  • 1217 Views
  • 1 replies
  • 0 Likes

Cortex XDR Agent certificate enforcement

Hi Team,

I have enabled the Cortex XDR agent settings for certificate enforcement. However, endpoints are showing as only partially protected, and the Operational Status Details indicate that certificate enforcement is disabled against policy (Failed

...

  • 2281 Posts
  • 86 Subscriptions
Top Solution Authors
Top Liked Authors