Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 482 Views
  • 0 replies
  • 2 Likes

XQL removes endpoint CVEs and ALL information

I want to remove all information related to the endpoint "ABC". However, with the following xql query, it only removes cves that are exclusively associated with this endpoint. If a cves is associated with multiple endpoints, the affected_products, af

...

Malware Scans


Hello community.
Do you know what the “scanning complete” column in the malware scan results refers to? I see that in the values it shows 3 folders, does that mean that it only scans those 3 folders? I attach evidence

R.Tuyub by L1 Bithead
  • 204 Views
  • 2 replies
  • 0 Likes

Cortex XDR on Citrix non-persistent multi-user server

Hi community

Quite often we have issues with cortex xdr on citrix infrastructure. Currently meinly with windows server 2022 we are in the situation where it is not possible to run cortex at all because of possibel servercrashes which are not yet anal

...

Remo by L7 Applicator
  • 1385 Views
  • 6 replies
  • 0 Likes

Question about folder exclusion

Hello Palo Live Community.

I need to exclude a folder along with all its subfolders and files of any type. To do this, I set up a rule similar to the following:
C:\Program Files (x86)\folder\*
However, I keep getting alerts about suspicious files insid

...

R.Tuyub by L1 Bithead
  • 217 Views
  • 2 replies
  • 0 Likes

Resolved! XTH licence allocation

Hi

We came to a conclusion that only handful of endpoints would benefit from the extra telemetries that add-on is collecting thus we do not want to purchase the add-on for the entire fleet.

Is it possible to allocate XTH add-on only on endpoints that

...

tmeksik by L2 Linker
  • 221 Views
  • 1 replies
  • 0 Likes

Resolved! Vulnerability Assessment Cortex XDR

I see there are two datasets regarding vulnerability assessment in Cortex XDR "va_cves" and  "va_endpoints" dataset. What is the difference between these two? Also is there some dataset or anything in Cortex XDR that I can use to find out if a CVE vu

...

Cortex xdr agent certificate

Hi all,

I have some doubts regarding the Cortex XDR agent certificate. I have gone through multiple blogs, which provided some insights, but I am still unable to see the complete picture. Below are the key facts I have gathered so far:

  1. New Certifica

...

On-demand file Examination policy

Hi,

 

I've got 3 questions.
1. I want to schedule a daily scan on servers with cortex xdr, I'm aware that Cortex only has options for weekly and monthly, so I tried creating a new profile for each day mapping them to the same servers but some are bein

...

jannette by L0 Member
  • 210 Views
  • 1 replies
  • 0 Likes
  • 2234 Posts
  • 86 Subscriptions
Top Liked Authors