Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Resolved! XDR Usecase Creation | XDR Rule

We have 3 use cases for which we want to set up 3 rules in XDR, we would like to get your help to identify the best avenue to address them :

  • UC 1 : deploy a rule that DETECT a behavior or IOC (ex: failed auth, file with specific SHA1...), AND generat
...

Constant Cortex XDR Agent upgrades

Hello,

I am working in an organization with about 25,000 machines installed with Cortex XDR solution.
Recently we have noticed that there are many frequent upgrades being rolled out within a short time span.
To date, we are still having trouble keeping

...

TIbrahim by L0 Member
  • 1158 Views
  • 1 replies
  • 0 Likes

Resolved! XQL query for cloud assets

Dear community,

 

I've trying to build an XQL query to search for the cloud assets that does not have XDR agent install.

From the GUI, these data is available under the following 2 locations:

- Cloud Inventory --> Specific Cloud Assets --> Compute In

...

Resolved! Understanding The Process Tree

Hello Everyone,

My intention is to fully understand the process tree naming convention for cortex XDR and the more I look at the logs the more confusing it becomes.

From my understanding the process tree from child to grandparent should look like below

...

  • 2078 Posts
  • 82 Subscriptions
Top Solution Authors
Top Liked Authors