Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Resolved! Block especific Process and Folder/directory

Hello community,

In our company we have implemented Cortex XDR with Pro per endpoint and pro per terabyte licenses.

the incident response area asks me to verify the viability of applying the following preventive measures in cortex xdr

1st. Block the exe

...

Agent 7.2 dont comunicate with broker vm

I proceeded to install cortex XDR on a Kali, respecting the installation parameter chmod + x Kali.sh - --proxy-list "proxysrv: 8080,10.250.1.34: 8080" However, the client cannot contact the broker the error it is a timeout. my query is the following,

...

romansad by L1 Bithead
  • 2238 Views
  • 6 replies
  • 0 Likes

Investigating ABIOCS

I'm investigating the cause of ABIOC alerts. We've seen one particular alert that appears to be a false positive but I'd like to get some more information to be sure and to understand these alerts better:

 

Name: Suspicious process accessed a site masq

...

DanBrook by L0 Member
  • 886 Views
  • 2 replies
  • 0 Likes

Resolved! Xdr ramsonware test is not detected

Hi. We recently we have acquired a solution to test our systems.
In one of the tests, we have detected that Cortex does not detect attacks, such as using util control with .net injection.
The test machine has created a malware profile with everything l

...

Backup software performance

One of our VMs seems to have its performance really impacted when backups run on a file server.  I do not readily see guidance for suggestions on how I might adjust Cortex XDR Prevent's settings to improve things since there is a fair amount of data

...