Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Access to live terminal with dual control

For legal reasons in our organization we have servers that can only be accessed in administrator mode if another authorized person authorizes access. That is, under no circumstances can a single person get administrator permissions.

Following this po

...

MSI stolen certificate alerts

Today we started to get alerts for all our MSI laptops with the reason: "Behavioral threat detected (rule: msi_stolen_certificate.1)". The alerts trigger on the MSI software installed on the latops, like "MSI center", or "One dragon center".

 

Are th

...

MRoberti by L0 Member
  • 788 Views
  • 2 replies
  • 0 Likes

PAN NGFW into XDR best practices

Hi there, 

 

We have have recently started ingesting PAN NGFW logs into XDR, however they're generating a lot of incidents, for now I have excluded - prevented/terminated events, does anyone have any information on best practices, useful ways to use

...

Deploying Cortex XDR via AutoPilot

I've been trying to configure Cortex XDR version 8.0.1.33809 to be deployed when configuring a laptop with autopilot. I downloaded the agent directly from Cortex XDR, configured it with the intune app creator to convert from an .msi file to a .intune

...

Resolved! System Threshold exception BIOC rules

I have once upon a time set the system threshold exception to 100 hosts. So when the same BIOC is triggered on 100 hosts at the same time, it automatically creates an exception. I would like to raise the number of hosts, but I cannot find the place t

...

DavidStevens_0-1684748059771.png

Cortex XDR Checkin Time

Hello All,

 

Was curious, is there a related registry key for Traps last check-in date? I'm curious if there is an easy way to pull in that information with powershell.

 

Quick example scenario would be that we would use one script to pull in the las

...

Amnsgna by L0 Member
  • 1176 Views
  • 3 replies
  • 0 Likes

XQL - what am I doing wrong?

Hello dear community!

 

I am testing some XQLs from the last webinar. 

In my test I fired following XQLs one on one, but I do not understand why the left join doesn't work. I allways get 7 results with the host inventory users preset. Without I get 1

...

RFeyertag by L4 Transporter
  • 1163 Views
  • 3 replies
  • 0 Likes

Resolved! XDR agent install using SCCM

Hi All, I would like to know if it's possible to install a new agent over an existing agent on a workstation. We have a specific situation where we enabled the auto-upgrade feature in our environment, but excluding our POS devices. 

 

To address the

...

Documentation for Advanced API Monitoring

Dear LIVE community,

 

Does anyone have any details on Advanced API monitoring? (Under Malware profile --> Global Behavioral Threat Protection Rules)

It is disabled by default and the only information we got so far was that it could help detect CVE-2

...

  • 1769 Posts
  • 78 Subscriptions
Top Liked Authors