Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4549 Views
  • 0 replies
  • 3 Likes

Understanding Inline Cloud Analysis C2 Detections and False Positives in Cortex XDR

Hi everyone, I am currently investigating several Cortex XDR incidents that originate from Palo Alto Networks Firewall Security Profiles, specifically detections related to Inline Cloud Analysis, Anti-Spyware C2 classifications. What I am trying to better understand is why a relatively large amount of legitimate-looking web traffic is being clas...

T.Fink by L1 Bithead
  • 1054 Views
  • 3 replies
  • 0 Likes

How to Query WildFire Malware Prevention Events Not Generated as Issues

Hello We are currently operating approximately 4,800 agents. During the initial deployment, a large number of false positives were generated by WildFire Malware events, so we applied an exception to prevent these events from being generated as Issues. However, we have recently received user reports of cases suspected to be blocked by this policy...

.522643 by L1 Bithead
  • 255 Views
  • 1 replies
  • 0 Likes

Resolved! Case resolution center - no recommendations

Hello. I have never seen any recommendations in the resolution center when reviewing cases. Respective playbooks are configured and enabled; however, there's nothing. Our Palo SME stated it might be an XSIAM thing and not and XDR Pro thing, but I feel like something should be there. Anyone have any insight to this or tips? Thank you.

XQL to get details of endpoint connection time

Hello Team, I need to create a report in Cortex XDR to identify endpoint connection activity within a specific time window. The requirement is not to know when the endpoint was first registered in Cortex, so `first_seen` does not apply here. What I need is to identify: 1. Endpoints that changed from DISCONNECTED to CONNECTED during the selected ...

Resolved! Cortex XDR Tenant Auto-Upgrade 3.17 → 5.0: UI mixed theme, AI pages stuck loading, Marketplace/Playbook Catalog empty + ingestion quota warning

I tried to open a Support case, but none of the available issue categories allowed me to create a case and I was redirected to Live Community for assistance. I’m posting here to get guidance on the likely root cause and recommended next steps. After an automated upgrade from 3.x to 5.0, multiple UI and feature issues appeared. Pages look like ...

XDR Agent Quota Exceeded

Hello, We receive numerous alerts of "XDR agent quota exceeded on ****" I understand this means that the default storage is being exceeded but what exactly does that entail? 1. Are the old logs not being overwritten in time causing the alert to set off since the space has been exceeded? is it actually going over the default space or is ther...

Resolved! Not seeing Cortex MCP Server Download

Hi all the Cortex MCP Server download under Settings → Configurations shows on commercial tenants but is missing entirely on our FedRAMP / Federal tenant (not a permissions issue). Is it on the roadmap for Federal environments, and is there an expected timeline for rollout? Thanks!

DLP (DataPatrol) signed DLL injection into Word blocked by agent — permanent exception?

Our DLP watermarks documents by injecting a signed DLL into WINWORD.EXE on print. The Cortex agent blocks the injection — page prints with no watermark, DLL never loads. Works fine with the agent removed. Persists in Report mode, generates no alert/prevention event. Tried a Disable Prevention rule (signer + thumbprint, all modules, global) — no ...

Resolved! Protection Mode for Linux Modules

When configuring Reverse Shell Protection and Malicious Child Process Protection there's an option to configure the protection mode. Default is "normal" but we could choose "aggressive" too. There's no documentation. Does anyone know the difference of protection modes for these Linux modules? Is it the same as in the ransomware protection modu...

micomi_0-1782802979178.png
micomi by L3 Networker
  • 358 Views
  • 1 replies
  • 0 Likes

Anyone else having XDR communication problems?

Starting later in the day on June 24, we started seeing endpoints show 'No connection to server' when opening the Cortex console on the endpoint. Endpoint tasks like collect firewall logs, pause protection and live terminal all fail. Some systems shows that they ARE connected to our tenant but trying to live terminal into them fails.

Any specific post-installation procedure / configuration required to make sure the protection running on Mac without affecting performance ?

Dear All, Having a few MacOS devices (iMac, MacBook Pro) installed with Cortex XDR agent v9.2.0 for piloting (procedure follow through https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/9.2/Cortex-XDR-Agent-Administrator-Guide/Install-the-Cortex-XDR-Agent-Manually) They are running on monitoring (without blocking on "malware profile" and ...

Cortex XDR and Sandboxie

Hello, We have installed Cortex XDR on a VM that also runs a sandbox tool (Sandboxie). As long as Cortex XDR is enabled, processes cannot be started within the sandbox (e.g., msedge.exe, cmd.exe, explorer.exe). It only works if I create a "Disable Injection and Prevention" rule for these processes. How can I resolve this permanently? I suspect...

M.Wempen by L1 Bithead
  • 403 Views
  • 2 replies
  • 0 Likes

Resolved! XDR agent disconnected after automatic upgrade

After automatic upgrade is performed an endpoint now is disconnected with this message: XDR Agent failed to upgrade from version 9.1.0.20483 to version 9.2.0.120 on 79433PC with error: The content package was faulty or could not be downloaded. Is there a way to reconnect it to XDR console?

Operational Exception without Case

We are currently facing an issue with a Windows service. This service only functions properly after we add a specific executable (.exe) to the Operational Agent Exceptions . We haven’t seen any corresponding case or alert in the console, meaning Cortex XDR is not actively blocking anything. This raises the following questions: 1) Wildcards in Op...

M.Wempen by L1 Bithead
  • 526 Views
  • 1 replies
  • 0 Likes
  • 2657 Posts
  • 101 Subscriptions
Top Solution Authors