Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by • Community Team Member
  • 4616 Views
  • 1 replies
  • 3 Likes

Cortex XDR MITRE ATT&CK v16 -- We're Now on v19. Can We Talk About This?

Hey LIVEcommunity, I have been sitting on this for a while and finally decided to write it up because I am pretty sure I am not the only one running into this. If you are a detection engineer or SOC analyst building BIOCs in Cortex XDR and leaning on MITRE ATT&CK to organize your detection coverage, this one is for you. So Here Is What Ha...

D.Ogle by • L0 Member
  • 1933 Views
  • 3 replies
  • 7 Likes

Sending case to a third party tickiting system

Hello, i hope you re doing well i want to know the steps to send cases when there generated to our third party tickiting system , how to do it via API or weebhook. can someone already worked on a similare case share with me all the steps and configuration required. thanks in advance Cortex XDR

Resolved! Cortex XDR and Microsoft Defender Coexistence and Performance

Hello Cortex XDR Community,We recently were asked to have official guidance regarding the coexistence of Cortex XDR Agent and Microsoft Defender on Windows endpoints. My questions to the community and experts is: - Is the coexistence of Cortex XDR and Microsoft Defender Antivirus officially supported? - Is the coexistence of Cortex XDR and Micr...

XDR Not Recognising Hotpatches

We've started deploying WIndows Enterprise Hotpatches to speedup the adoption of patches and reducing the number of reboots required. Howver, XDR doesn't recognise the Hotpatches and is telling us that the endpoints are still vulnerable. This is a known "limitation" according to support. What are others doing in this space please?

I just received this alert "Script Activity - 245655498" with this description "Suspicious script with keywords written in a non-standard way." in Cor

I just received this alert "Powershell Activity - 2390140751 " with this description "Suspicious script with keywords written in a non-standard way." in Cortex multiple times related to PowerShell script execution on a developer machine. The executed scripts were different and I don't know why Cortex is blocking such executions. There is also no...

Multiple Cortex XDR Agent Upgrades Failing with "The installer has timed out" Error

Hi team, We are currently encountering a mass upgrade failure across multiple endpoints during both Auto Upgrade and Manual Server Upgrade attempts. While a single endpoint successfully upgraded using our standard profile and group configuration, the remaining endpoints consistently fail. Issue Summary: Symptom: The upgrade tasks transition to...

Z.Zikri by • L0 Member
  • 436 Views
  • 1 replies
  • 0 Likes

Resolved! Cortex XDR Pro – Does it scan USB devices upon insertion?

Hi team, I would like to confirm the behavior of Cortex XDR Pro regarding USB devices: Does Cortex XDR perform any automatic malware scan when a USB device is connected to an endpoint? If not, what protections are applied at connection time (e.g., device control, behavioral detection, execution monitoring)? Is scanning of removable media only p...

Resolved! Sending cases of MDR Unit 42 Managed Services cortex XDR to tickiting system

Hello, I hope you all doing well, i want to send case investigated by MDR to our internal tickiting system (regardless of it, the importing that it support API, webhook ...). Can you please share a refference or documentation on how to do it on cortex side, and the configuration i need to deploy on Cortex XDR. Best regards,

Resolved! Cortex XDR agent protection after 90 days of inactive

Hello Everyone. I need your opinion to this topic. What will happen to the agent protection for the endpoint after 3 months of inactive. Correct me if im wrong. Cortex XDR agent will delete permanently from management console and database after default deletion which is 90 days. if i enable all the module in day 1 for an endpoint, then af...

Cortex XDR Policy - Executables blocked from removable media

Hi, As the name suggests, we have a policy to block executables from removable storage. While it works great, there are issues arising when a user wants to install drivers for printers, scanners etc. Since as soon as a device is connected for the first time, it gets mounted as a storage drive. Is there a way to allow only such devices to be ad...

  • 2663 Posts
  • 102 Subscriptions
Top Solution Authors
Top Liked Authors