Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4327 Views
  • 0 replies
  • 3 Likes

Local Analysis Malware and WildFire Malware Alerts

Can someone explain the Local Analysis Malware and WildFire Malware alerts. The WildFire alerts seem straightforward for a file that it deems malware. On the other hand, the local analysis malware alerts trigger for a bunch of files but in the alert it has a wildfire report and verdict that says benign. Moving into suppressing these alerts, the ...

Resolved! XDR Endpoint with Containers

Hello, I would like your help to understand what protections I have with Cortex XDR Endpoint Pro on a Linux server running containers/Docker. Will XDR also protect against malicious activity originating from the container to the network, or is it more of a black box?

tlmarques by L4 Transporter
  • 926 Views
  • 5 replies
  • 0 Likes

Cortex XDR - Sharing IOC with Other Tenant

Hello Palo Alto Team, I just want to ask a question regarding sharing IOC with other tenant. Is it possible to share continuously IOC with other tenant? If it possible, please share with me, because I have case that need to share IOC to tenant in other region under Pertamina Hulu Energi that have also their Cortex XDR. Thanks

A.Faruq by L1 Bithead
  • 350 Views
  • 3 replies
  • 0 Likes

Ingest GlobalProtect logs to Cortex

Hi. We are ingest data from Paloalto Firewall which using GlobalProtect feature and now we need send logs through Broker Vm setup. We can't use native integrations so syslog is only option. We get data and i see that dataset is > dataset = palo_alto_networks_lf_raw and i notice that not work with example some detection rules, so that is not ...

T.Nurmi by L2 Linker
  • 770 Views
  • 1 replies
  • 0 Likes

SBAC limitations: Delegation of full control (profiles and exceptions) for a specific group of endpoints.

Hello community! I'm looking for the best way to delegate Cortex XDR administration to an IT team within a specific department. The goal is to give them full control over a particular group of endpoints, ensuring strict separation: they shouldn't have visibility into or the ability to manage the endpoints in the main network. The problem: I've b...

cyvrlpc.sys failure

Our IT department supports a OurDesktop virtual environment. I was notified of an error that has been coming up during multiple sessions. It acts somewhat like a BSOD in that it shows an error then reboots the computer for you. No configuration changes were made. Running v8.9 in this environment. Stop code: SYSTEM_SERVICE_EXCEPTION (0X3B) What...

Resolved! Configuration/Whitelistings accross mutliple Cortex Tenants

Hello everyoneI am working in an MSSP environment and managing several Cortex XDR tenants. While reviewing the official Palo Alto Networks documentation and online resources, I couldn’t find any information about whether it is possible to create configurations (such as exceptions, exclusions, custom detections likes BIOCs etc.) once and apply th...

MaaHaa by L0 Member
  • 1257 Views
  • 1 replies
  • 0 Likes

Issue with IOC not blocking MyPDFSwitch executable

Hello, I have been receiving alerts related to a file named MyPDFSwitch_8173674.exe, where the filename ends with random numbers. I created an IOC with the following pattern: MyPDFSwitch*.exe However, today I received another alert related to this file, so I suspect that the IOC is not working properly. Could you please advise what might be happ...

Cortex XDR Uninstall without password and active tenant

On Windows computer we have installed the cortex XDR agent on POC tenant.The tenant was deleted but we don't uninstalled the agent on the client computer.We try to uninstall it manually, but we don' have the password.We try with the default password, but we can't. Any idea to uninstall ? #Cortex #Cortex XDR #uninstall

LABRIC by L0 Member
  • 54381 Views
  • 8 replies
  • 0 Likes

Resolved! Up-to-date detections for TeamPCP malware used in Trivy and Checkmarx compromises available?

Hi, we're currently using the data collected via XDR and other sensors to hunt for IOCs of the recently observed attacks against aquasecurity Trivy Github actions, as well as Checkmarx KICS. This, obviously, focuses mainly on network-based IOCs like C2 domain and IPs, as well as file hashes and version strings in filenames.However, the attackers...

Enable access to required PANW resources Cortex

I would like to deploy an XDR For IP address ranges in Google Cloud Platform (GCP), refer to these lists for IP address coverage for your deployment: https://www.gstatic.com/ipranges/goog.json: IP address subnet ranges https://www.gstatic.com/ipranges/cloud.json: IP address ranges associated with your region Should I use all the IP addres...

KVishwan by L0 Member
  • 471 Views
  • 1 replies
  • 0 Likes

Adding dynamic groups to XQL output?

Looking to add the dynamic groups assigned to endpoints as a field in an XQL query. Here is what I have right now below. I'm unable to figure out if there is a way to get the dynamic group names in there. That would help us find machines easier than using the GUI method as this is a single report instead of trying to combine multiple exports due...

J.Suter by L2 Linker
  • 609 Views
  • 3 replies
  • 0 Likes

Inconsistent AnyDesk Detection in Cortex XDR

Hi everyone, I'm observing inconsistent detection behavior in Cortex XDR during weekly on-demand scans related to the AnyDesk application. On some endpoints, AnyDesk is detected as "Suspicious executable detected", while on others no alert is generated, even though the application is present. One common pattern we observed is that the alerts are...

Resolved! Try to install the Cortex MCP server

Hi all, I try to use "Cortex MCP server" for testing purposes. https://docs-cortex.paloaltonetworks.com/r/Cortex/Cortex-MCP-server/Install-the-Cortex-MCP-server I use a Docker installation on Windows 11. What I've done so far: - Created and copied the API URL, API key, and API key ID. - Downloaded and extracted the MCP zip file: - I c...

Screenshot 2026-03-20 112535.png
Screenshot 2026-03-20 103758.png
PeterMS by L1 Bithead
  • 2023 Views
  • 1 replies
  • 0 Likes
  • 2591 Posts
  • 97 Subscriptions
Top Solution Authors