Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4319 Views
  • 0 replies
  • 3 Likes

Malware Scans

Hello community.Do you know what the “scanning complete” column in the malware scan results refers to? I see that in the values it shows 3 folders, does that mean that it only scans those 3 folders? I attach evidence

R.Tuyub by L1 Bithead
  • 942 Views
  • 2 replies
  • 0 Likes

Cortex XDR on Citrix non-persistent multi-user server

Hi community Quite often we have issues with cortex xdr on citrix infrastructure. Currently meinly with windows server 2022 we are in the situation where it is not possible to run cortex at all because of possibel servercrashes which are not yet analyzed and resolved. So we needed to - at least temporary - change to microsoft defender. I wanted ...

Remo by L7 Applicator
  • 4035 Views
  • 6 replies
  • 0 Likes

Resolved! Modification of default scoring for Alert-->Malware--Suspicious Executable Detected

I am looking for a way to modify the severity score for the alert in category Malware, named Suspicious Executable Detected. By default, this stamps the alert with a MEDIUM severity and therefore creates an Incident with that Severity. I would like to manage the severity level of this alert, so that it is a HIGH severity, as at MEDIUM it does no...

DuncanGM by L0 Member
  • 1219 Views
  • 2 replies
  • 0 Likes

Question about folder exclusion

Hello Palo Live Community. I need to exclude a folder along with all its subfolders and files of any type. To do this, I set up a rule similar to the following:C:\Program Files (x86)\folder\*However, I keep getting alerts about suspicious files inside this folder.Does anyone know why this is happening, could the rule be structured incorrectly? F...

R.Tuyub by L1 Bithead
  • 842 Views
  • 2 replies
  • 0 Likes

Resolved! Automatic Artifact Analysis in Forensic Investigation

I have created and conducted some forensic cases on Cortex XDR, but one thing that has always intrigued me is the "Alert" tab in the Forensic Investigation section. Does this tab contain alerts generated by the automatic artifact analysis feature based on behavior rules? And how can I utilize this feature, as I have never seen any alerts appear ...

Resolved! XTH licence allocation

Hi We came to a conclusion that only handful of endpoints would benefit from the extra telemetries that add-on is collecting thus we do not want to purchase the add-on for the entire fleet. Is it possible to allocate XTH add-on only on endpoints that need telemetries the add-on provides? Thanks Tum

tmeksik by L2 Linker
  • 1035 Views
  • 1 replies
  • 0 Likes

Resolved! Vulnerability Assessment Cortex XDR

I see there are two datasets regarding vulnerability assessment in Cortex XDR "va_cves" and "va_endpoints" dataset. What is the difference between these two? Also is there some dataset or anything in Cortex XDR that I can use to find out if a CVE vulnerability is being actively exploited on an endpoint?

Cortex xdr agent certificate

Hi all, I have some doubts regarding the Cortex XDR agent certificate. I have gone through multiple blogs, which provided some insights, but I am still unable to see the complete picture. Below are the key facts I have gathered so far: New Certificate Enforcement: Cortex XDR enforced a new certificate because the old certificate was vulnerable...

Resolved! Appcrash Windows event log entry for "cyinjct.dll"

Hello, I'm wondering if anyone ever had this problem. Appcrash event is occurring for "cyinjct.dll": Host: Windows Server 2019 Cortex Agent version: 8.7.0.7735- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">- <System><Provider Name="Application Error" /><EventID Qualifiers="0">1000</EventID&g...

[Cortex XDR] - I Want to monitor the file creation, modification, removal, etc. under the specified path through the BIOC Rule.

Dear Everyone, I would like to use the XDR BIOC Rule to block the host from creating, editing, deleting, renaming, etc. files in specific file paths. I tried to write a BIOC Rule but found that it can't be successfully applied to the Restrictions profile, and there is no Alert generated due to the matching of this rule, does anyone know why it...

On-demand file Examination policy

Hi, I've got 3 questions.1. I want to schedule a daily scan on servers with cortex xdr, I'm aware that Cortex only has options for weekly and monthly, so I tried creating a new profile for each day mapping them to the same servers but some are being scanned, other are not. What might be the reason?2. Also for them to work do I have to always r...

jannette by L0 Member
  • 1178 Views
  • 1 replies
  • 0 Likes

Legacy Agent Exceptions or New menu??

Hi, what's your opinion? Legacy Agent Exceptions or Global Exceptions Menu?? What's the difference? Which one is better? Some support people suggest activating Legacy in Cortex XDR #, but I'm not sure if I should. Would I lose any of the settings already configured in the other menu

tlmarques by L4 Transporter
  • 1932 Views
  • 3 replies
  • 0 Likes

Alert for Any PowerShell Script Execution in Cortex XDR

Hi Cortex XDR Community, I want to set up an alert in Cortex XDR that triggers whenever any user runs a PowerShell script. The alert should activate for any script or command executed in PowerShell, regardless of the user or specific script. Is there an existing rule or method to create such an alert for PowerShell usage? Any suggestions or exam...

  • 2583 Posts
  • 95 Subscriptions
Top Solution Authors