Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4319 Views
  • 0 replies
  • 3 Likes

Impossible uninstall Cortex XDR

Hello, Because of my previous work, I had to install Cortex XDR to work remotely from home and access to the VPN. Now that I'm no longer working for them, I would like to uninstall Cortex XDR from my laptop (MacBook Pro M2) but it is impossible. I tried to install the uninstaller but it impossible, the installation don't ever finish. Someone...

Rixals by L2 Linker
  • 10460 Views
  • 25 replies
  • 0 Likes

CVEs for applications Unsupported Platform

We have quite a bit of different softwares installed here, many Adobe products, 7-zip etc which I know have CVEs issued. Do I need to do something to enable this feature in XDR? ALL of the software detected shows Unsupported Platform. Does this feature actually work?

DopedWafer_0-1737557531926.png

is there a way to block Ethernet to USB type C in cortex ?

Hi, We have a cortex XDR installed in our network that will block all the storage devices. Also, we have the restriction to access internet sites through firewall. However, recently i came across an incident that one user connecting his own router using Ethernet to USB type C cable converter to access all the blocked websites within the orga...

Linux Agent Tampering protection

Hello Palo Alto Live Community, I hope this post finds you well. I’m currently exploring the tamper protection capabilities of Cortex XDR for Linux and would appreciate insights from this knowledgeable community. Specifically, I am interested in understanding: What features does Cortex XDR provide to prevent tampering with its agent or conf...

Identify users who changed their password in the last 48 hours

Hi! I am having difficulty performing an activity that consists of: I have an XQL query that validates unsuccessful logon attempts using EventID 4625. This query is functional and searches the logs for the last 7 days. I need to add a filter to this query that identifies whether the user has had their password changed in the last 48 hours, using...

XQL 2 Datasets

Hello community,I am reaching out to you after many hours of trying to get this XQL query but something is not working.I need to join the IP address from endpoints to my query dataset = management_auditing | filter description contains "SOX" and (description contains "assign tags" or description contains "remove tags") | alter HOSTNAME = if(desc...

Disable notification in user agent

Hello,I have an exception rule on a file that is being applied correctly. The file executes because of this exception, but in the user agent you get a warning that an unusual activity has been encountered or that a malicious activity has been encountered even though the file executes.How can you prevent the user from getting this notification? T...

Agent stops because of full storage

Hi, We recently encountered an issue where an XDR agent stopped functioning, and all protections were disabled (except for tamper protection) due to a full temp folder. Has anyone experienced a similar problem and identified the root cause or potential solutions? To resolve the issue, we disabled tamper protection, manually cleared the temp fo...

paIoaItonetworks_1-1736243068553.png

Cortex XDR Issues with macOS Sequoia 15.2 and Airplay

We’ve noticed that with Cortex XDR installed on a MacBook running macOS Sequoia 15.2, AirPlay functionality no longer works for presentations. When attempting to connect to Apple TV via AirPlay, the connection times out. The native macOS firewall is enabled. However, when Cortex XDR is not installed, the issue does not occur. Has anyone else en...

FTP Transfer Custom BIOC

Hello Palo Alto LiveCommunity, I’m currently working on a task where I need to create a custom BIOC (Behavioral Indicator of Compromise) and add it to a restriction profile to block FTP command lines. Specifically, I want to prevent FTP-related commands from being executed by monitoring and restricting certain patterns. I also need help with...

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4319 Views
  • 0 replies
  • 3 Likes

LSA Protection and antimalware DLL loading

We currently have deployed LSA Protection and code integrity in Windows 11 (build 24H2). Cortex XDR agent 8.6.0 is installed. When trying to load a DLL from another security tool (Ivanti Device and Application Control), Code Integrity is blocking the action with the following error: Code Integrity determined that a process (\Device\HarddiskVol...

error.PNG
  • 2582 Posts
  • 95 Subscriptions
Top Solution Authors