Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Resolved! Xdr ramsonware test is not detected

Hi. We recently we have acquired a solution to test our systems.
In one of the tests, we have detected that Cortex does not detect attacks, such as using util control with .net injection.
The test machine has created a malware profile with everything l

...

Backup software performance

One of our VMs seems to have its performance really impacted when backups run on a file server.  I do not readily see guidance for suggestions on how I might adjust Cortex XDR Prevent's settings to improve things since there is a fair amount of data

...

Quarntine Malicious file detected by scan

Hi all,

When I initiate a scan to a machine a the action of malicious file is Detected (Scanned) but it is not getting quarantine although we enabled the quarantine malicious files in Behavioral Threat Protection.
Anyone know the reason ?

Thank you,

Resolved! Broker VM and SSL Certificates

Hello PAN Community,

 

I am trying to import SSL certificates to Broker VM. However, when I try to import Private Key, it does not prompt me for the password. Does this mean I have to export the Private key without requirement for passphrase? 


Thanks.

D

DKasabji by L2 Linker
  • 1279 Views
  • 2 replies
  • 0 Likes

Integrating multiple Cortex XDR with QRadar

Hi,

 

Thought I would give livecommunity a shot on this. We have been looking into integrating several Cortex XDR instances into a single QRadar instance but have come across an issue where it does not seem to let us change the syslog identifier name o

...

Edmund66 by L0 Member
  • 1087 Views
  • 1 replies
  • 0 Likes

Device Control

Can Cortex XDR prevent the use of other USB devices other than Disk Drives, CD-Rom Drives, and Floppy Disk Drives? If one of my users plugs in a printer, can that be denied? Can the same be done with SD cards?

 

XDR Network location configuration & VPN

Hello!

 

On all our endpoints we are using XDR with firewall(Uses built in Windows firewall) and Palo Alto GlobalProtect VPN connecting to PanOS devices at our office. We use split tunneling for the VPN, that means that only specified traffic goes thro

...

mdsgn1 by L0 Member
  • 1002 Views
  • 2 replies
  • 0 Likes

XDR policy targeting using AD

Hi there,

 

When we are trying to target a policy using AD group some of the listed endpoints is not a member of selected group.

To get more clarity we selected a group which only contains users and even then the result listing some random endpoints.

Is

...

HafisM by L0 Member
  • 1017 Views
  • 2 replies
  • 0 Likes

Cortex XDR with Carbon Black

Hi All,

  I know it is a stupid question but I am encountering this situation that we need to install Cortex XDR working with Carbon Black (it's a long story). May I know if anyone experienced this before or any suggestions on exclusion? Thank you so

...

Resolved! Cortex XDR report

Hello Live community,

 

I have a question about the report on Cortex, i want to know if the “Infected Endpoints” comes as default in Cortex reports or if we need to configure something to show that option?

Do the widgets "incidents by source" or "Top in

...

Top Liked Authors