Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4322 Views
  • 0 replies
  • 3 Likes

UNKNOWN USB DEVICE tdevflt.sys

Hi, i´ve a USB port problem. I´ve already update all the lenovo drivers both automatically and manually and it didn't work. The PC keeps blocking me the USB ports. When i was looking for the solution, we tried to disable the cortex agent and after a restart the issue stops, the PC automatically detect the USB device and there´s no error in the d...

Broker Link

Hi, I need a method to identify endpoints in my environment that are not communicating or linked the broker but Cortex is installed, noting that those machines do not have internet access. Thanks,

URL & Application level blocking possibilities in Cortex XDR.

Hi All, Hope you all are doing good. Can anyone help me to understand the possibilities of url and application-level blocking in XDR? Following are my scenarios, 1. Blocking of URLs in XDR. 2. Blocking of execution/installation of specific applications in XDR. 3. Blocking of applications running without installation.(eg. anydesk applicati...

Aneesh by L1 Bithead
  • 6459 Views
  • 5 replies
  • 2 Likes

XDR Agent Auto Upgrade installer has timed out.

Hi everyone, I have a customer who has configured the automatic upgrade of XDR Agent, when the new version is released, only a small number of Agents have completed the upgrade, a large number of Linux hosts have failed to upgrade, and the Last Upgrade Failure Reason shows "The installer has timed out.", I tried to find the reason for this pro...

yuyangab by L1 Bithead
  • 3932 Views
  • 4 replies
  • 0 Likes

Resolved! Does Cortex XDR support encrypted macros?

Getting this Office warning when trying to open a file containing an encrypted macro. Are they supported? If they are then why does the MS Windows Antivirus API incorrectly report? The host has Cortex XDR Agent 8.6.1 installed.

DanRoberts_0-1738314316381.png

XDR Grafana Auth error

Hi everyone, i need your help, i've see all posts related with grafana and Cortex XDR and i've one problem. When i try authenticate with API , using postman, and set enviroment, the post for get endpoints works...but grafana not work. but when i not use the enviroment variables, and force only the flags one header, the system not work (usi...

tlmarques by L4 Transporter
  • 842 Views
  • 1 replies
  • 0 Likes

Unable to retrive downloaded exe's

Hello everyone, I was trying to check all the downloaded exe's via firewall on all the endpoints in past 24hrs. I tried retrieving all downloaded exe's in downloads folder with the help of this query below. dataset = xdr_data | filter event_type = ENUM.FILE | filter action_file_path contains "Downloads" and action_file_path contains "C:\Users...

XDR & Java installs

With the upcoming Oracle Java license changes, I'm looking into using XQL to report on existing installs, and potentially a process based BIOC to block new installs which would incur a licensing fee. Anyone familiar with Java know how to differentiate between openJDK installs and OracleJDK installs?

SearchHost.exe

Hello Everyone, I am new to Cortex XDR. I wanted to ask what is searchHost.exe? and if it is safe when it generates alarm (level Medium) in Cortex XDR? If not then any recommendations? Thanks

Uninstall Cortex XDR Agents from endpoints programmatically

Hi, I would like to programmatically uninstall agents from endpoints but are running into dead ends. Currently, based on the documentation (https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Uninstall-the-Cortex-XDR-Agent), we are only able to uninstall the agent via the Action Center or Endpoints page. ...

USB protection exeption for ClickShare usb Device

Hello everybody, if we block USB Drives/Windows drives our ClickShare (USB Screen Share Dongle) devices also get blocked. But they don´t appear in the "Device Control Violations" list so we can´t exclude them from blocking. We tried to exlude the path for the *.exe on the ClickShare but this seems not to work. How can we exlude these ClickS...

D.Meyer by L1 Bithead
  • 4009 Views
  • 8 replies
  • 0 Likes
  • 2587 Posts
  • 95 Subscriptions
Top Solution Authors