Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4356 Views
  • 0 replies
  • 3 Likes

Resolved! Configuration/Whitelistings accross mutliple Cortex Tenants

Hello everyoneI am working in an MSSP environment and managing several Cortex XDR tenants. While reviewing the official Palo Alto Networks documentation and online resources, I couldn’t find any information about whether it is possible to create configurations (such as exceptions, exclusions, custom detections likes BIOCs etc.) once and apply th...

MaaHaa by L0 Member
  • 1315 Views
  • 1 replies
  • 0 Likes

Issue with IOC not blocking MyPDFSwitch executable

Hello, I have been receiving alerts related to a file named MyPDFSwitch_8173674.exe, where the filename ends with random numbers. I created an IOC with the following pattern: MyPDFSwitch*.exe However, today I received another alert related to this file, so I suspect that the IOC is not working properly. Could you please advise what might be happ...

Cortex XDR Uninstall without password and active tenant

On Windows computer we have installed the cortex XDR agent on POC tenant.The tenant was deleted but we don't uninstalled the agent on the client computer.We try to uninstall it manually, but we don' have the password.We try with the default password, but we can't. Any idea to uninstall ? #Cortex #Cortex XDR #uninstall

LABRIC by L0 Member
  • 54810 Views
  • 8 replies
  • 0 Likes

Resolved! Up-to-date detections for TeamPCP malware used in Trivy and Checkmarx compromises available?

Hi, we're currently using the data collected via XDR and other sensors to hunt for IOCs of the recently observed attacks against aquasecurity Trivy Github actions, as well as Checkmarx KICS. This, obviously, focuses mainly on network-based IOCs like C2 domain and IPs, as well as file hashes and version strings in filenames.However, the attackers...

Enable access to required PANW resources Cortex

I would like to deploy an XDR For IP address ranges in Google Cloud Platform (GCP), refer to these lists for IP address coverage for your deployment: https://www.gstatic.com/ipranges/goog.json: IP address subnet ranges https://www.gstatic.com/ipranges/cloud.json: IP address ranges associated with your region Should I use all the IP addres...

KVishwan by L0 Member
  • 555 Views
  • 1 replies
  • 0 Likes

Adding dynamic groups to XQL output?

Looking to add the dynamic groups assigned to endpoints as a field in an XQL query. Here is what I have right now below. I'm unable to figure out if there is a way to get the dynamic group names in there. That would help us find machines easier than using the GUI method as this is a single report instead of trying to combine multiple exports due...

J.Suter by L2 Linker
  • 654 Views
  • 3 replies
  • 0 Likes

Inconsistent AnyDesk Detection in Cortex XDR

Hi everyone, I'm observing inconsistent detection behavior in Cortex XDR during weekly on-demand scans related to the AnyDesk application. On some endpoints, AnyDesk is detected as "Suspicious executable detected", while on others no alert is generated, even though the application is present. One common pattern we observed is that the alerts are...

Resolved! Try to install the Cortex MCP server

Hi all, I try to use "Cortex MCP server" for testing purposes. https://docs-cortex.paloaltonetworks.com/r/Cortex/Cortex-MCP-server/Install-the-Cortex-MCP-server I use a Docker installation on Windows 11. What I've done so far: - Created and copied the API URL, API key, and API key ID. - Downloaded and extracted the MCP zip file: - I c...

Screenshot 2026-03-20 112535.png
Screenshot 2026-03-20 103758.png
PeterMS by L1 Bithead
  • 2123 Views
  • 1 replies
  • 0 Likes

Resolved! E token Cortex XDR blocking

In our Organization E-Token is widely used by different departments/branches for specified purpose .However our cortex XDR is blocking the same under CD ROM category . How to allow the same and where to allow.

MEERSHAH by L0 Member
  • 794 Views
  • 1 replies
  • 0 Likes

Integrating VirusTotal with Cortex XDR

Hi Guys,In the Artifacts section we are not able to see the VT Score . For this we are manually copying the IP's , Hashes & viewing in the Virustotal console.Got to know we need to configure the API key but the concern is what data does Cortex XDR submit to VT ?only hashes , IP's or it will upload the entire file ?What are the precautions/be...

Resolved! PLease Correct the XQL query I have Created for the objective

Hi Community, I want to implement this objective so developed two queries with regex and non regex but it is giving tons of logs, can anyone help me on fine tuning or change the queries or correct them. Thank you Destructive Wipe / Anti‑Recovery Utilities Objective To detect destructive actions where adversaries attempt to wipe data or remo...

Resolved! Help me on developing XQL Query

Hi Community, Please help me on creating XQL query for cortex XSIAM on the below requirement. VPN Credential Abuse / Anomalous VPN Access Objective:Detect initial access via compromised VPN credentials, the primary entry vector used by Handala Hack. It looks for suspicious VPN authentication events such as first‑time logins from new geolocati...

Resolved! Please help me on developing xql query for cortex xsiam

Hi Community, Please help me on developing the xql query for cortex xsiam on the below objective. RDP Lateral Movement Burst Objective Detect high‑velocity RDP lateral movement, It detects multiple RDP connections (logon type 7/10) from the same account within short time spans, lateral movement to multiple hosts, and privilege misuse associat...

Resolved! Windows Event Collector vs XDR collector

Hello guru, it seems both served the same purpose to me. all i would like to ingest the event logs for analystic purpose. except the configuration nature, like WEC required AD config and XDR collector need an agent installed. what is the pros and cons for for WEC and XDR collector? any use case for each? thanks SdG

  • 2599 Posts
  • 98 Subscriptions
Top Solution Authors