Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Cortex XDR Alerts - Slack Integration

Is there any way to include the hostname for alerts received in Slack? They are very valuable to receive on the phone late at night, but would be even better if we had a bit more information: hostname, domain, something that indicates this is a test

...

unable to alert on Device Control Violations

support says it is by design

the "Traps Logs Formats" kb makes no reference to them either

before I go through the headache of sending cortex logs to something for alerts can anyone confirm that they will even be present?

anyone have any other ideas on

...

jp1151 by L0 Member
  • 1177 Views
  • 1 replies
  • 0 Likes

Exceptions "Child process"

Hello!!

 

How are you?  i need confirm an action when add exception for child process, i have several alerts for "WmiPrvSe.exe Rare Child Process" that are false positive, and im considering add to whitelist in the profile associated.

 

 

For create it i

...

Julitro_0-1598461562310.png
Julitro by L0 Member
  • 1140 Views
  • 1 replies
  • 0 Likes

Resolved! Extend Ransomware Protection to SMB Shares

I noticed that my tenant space has a new option in the Windows Malware Profile under Ransomware Protection that is named "Extend Ransomware Protection to SMB Shares".  I don't believe this setting was available prior tot he 7.2 release that I read ab

...

initial profiling?

when you first install the Cortex XDR agent on a new server (and reboot if on Windows), is it immediately 'active' and blocking suspicious processes? I was told that it ran in 'passive' mode for 30-days as it built a profile of "normal" activity for

...

Signature Weak hash

Good day! community,

 

I have a question, what treatment is given to executables that are signed as weak hash?

I understand that cortex XDR will block its execution.

Can it be excepted considering that it is a utility software?

The hash is unaltered and W

...

Resolved! Vulnerability Assessment

Hi experts, 

 

Cortex now has the ability to report vulnerabilities on endpoints, currently limited to Linux endpoints. 

 

Does anyone know if this is going to be extended to Windows and other endpoint types? 

 

Thanks

 

Darren 

BizBo by L2 Linker
  • 1411 Views
  • 1 replies
  • 0 Likes
Top Liked Authors