Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4526 Views
  • 0 replies
  • 3 Likes

Need XdrAgentCleaner.exe for Cortex XDR agent version 7.9.1 - Anti-Tampering enabled

Hi everyone, I'm an IT technician and I'm trying to uninstall Cortex XDR agent version 7.9.1.26645 from a Windows 11 workstation. Unfortunately, I'm facing the following issues: - The standard uninstall from Programs & Features fails with: "Anti-Tampering is enabled. Please disable Anti-Tampering and retry the operation." - cytool protec...

Resolved! After more than 2 years Linux vulnerability reporting is still useless.

It is about 2 years ago that the Linux vulnerabilities reporting issues where announced to Palo Alto.It's still not fixed. 😞It looks like Cortex does not look beyond the dash in the version numbers of installed applications. For example; Cortex is reporting a vulnerable zlib 1.2.11The one actually installed was: zlib.x86_64 1.2.11-40.el9which ...

Resolved! Local Analysis and Exceptions

Hey,we are struggling with the following Case with understanding local Analysis, Macros and writing a useful exceptions. Local Analysis is alerting on a WinWord.exe with "Macro(s) in Winword.exe". The Macro is only mentioned by hash. Exception with Disable Prevention Rules for local analysis on the macro hashes are not working, similarly on Wi...

J.Motz by L0 Member
  • 523 Views
  • 1 replies
  • 0 Likes

Reports no longer shows the source of an incident

Hello, One of our customers pointed out that since the 5.0 update of the Cortex console, the report output has changed.Before the update, the reports always displayed the source of the incident (as highlighted in the “Before.png” file). Since the 5.0 update, as you can see in the “Now.png” file, the source of the incident is not always displayed...

C.PAPET by L0 Member
  • 560 Views
  • 1 replies
  • 0 Likes

Resolved! Local Analysis Malware - Signed exe

Hello, we have following case: The "Local Analysis Malware" module blocks a self-developed, unsigned tool. However, after signing the tool with our own certificate, it is no longer blocked—even though we have not added or configured this certificate in any of the policies. How can this behavior be explained? Does Cortex integrate with or ref...

M.Wempen by L1 Bithead
  • 771 Views
  • 2 replies
  • 0 Likes

On-write file examination / cross-platform examination for Linux

Dear LIVEcommunity Has anyone been able to test out the new Linux / MacOS cross-platform examination module? I created a new Linux Malware Profile and set the "On-write File Examination" for "Portable executable files (Windows)" to Enabled, applied it to a policy for my Linux endpoint, waited for the policy to apply and then copied a WildFire ...

andreal by L1 Bithead
  • 539 Views
  • 2 replies
  • 0 Likes

Resolved! bioc not prevent

Hi everyone, i've created this bioc: dataset = xdr_data | filter event_type = ENUM.LOAD_IMAGE | filter ACTOR_PROCESS_COMMAND_LINE contains "netsh" and ACTOR_PROCESS_COMMAND_LINE contains "advfirewall" and ACTOR_PROCESS_COMMAND_LINE contains "set" and ACTOR_PROCESS_COMMAND_LINE contains "currentprofile" and ACTOR_PROCESS_COMMAND_LINE contains...

tlmarques by L4 Transporter
  • 717 Views
  • 1 replies
  • 0 Likes

How to add exception for known macros detection by cortex XDR

We are facing alerts for some excel enabled macro files are getting blocked in local analysis which is known and signed. After certain time file verdict changed to benign but still its triggered in local analysis and user unable to execute it. Please help us how to unblock this without adding specific path under exception. Thanks

Cannot add BIOC rule to restriction profiles

Hello, I'm receiving malware incidents with files signed by the same signer entity. However, Cortex XDR often only detects these files without blocking them. I want to prevent this behavior by creating a BIOC rule that detects processes with that specific signer and converting it into a prevention rule. However, when I try to add the BIOC rule...

SAlves_0-1778845767968.png
S.Alves by L0 Member
  • 568 Views
  • 1 replies
  • 1 Likes

Application Fingerprinting

Hello Community, I want to understand if application fingerprinting can be achieved in cortex. If yes, what is the approach of achieving default block for all the unknown application. Thanks and Regards.

Dead Space

This has been bothering me for a while. Look at all this useless space that is taken up now! 1/3 of the screen is useless. I wish I could scroll it away, but we are forced to deal with it. The information I need to actually review is even further down in the bottom 40% of the screen.

GPereira950193_0-1778519819702.png
  • 2640 Posts
  • 101 Subscriptions
Top Solution Authors