Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 276 Views
  • 0 replies
  • 2 Likes

Resolved! PortableApps - Block all

Hello, I would like to know if anyone has ever blocked portable applications...

We would like to block PortableApps (PortableApps.com)... without blocking them one by one, as there are many. Has anyone ever blocked them using a wildcard in the proce

...

tlmarques by L4 Transporter
  • 1134 Views
  • 1 replies
  • 0 Likes

Can XDR replace Trend Micro Deep Security

Hi Team,

 

Our client has both Trend Micro Deep Security and Cortex XDR installed on their servers and is evaluating the feasibility of just keeping the XDR.

 

Trend Micro has the following modules on them, kindly let me know if XDR also has these- 

...

Cortex XDR opt disk space issues

Hello Team ,

 

Is there anyone also facing issues with opt file system where Cortex XDR directory is consuming lot of space and getting full?  How we can remove or free up space for Cortex XDR directory in opt ?

There are multiple use cases where opt

...

Cortex XDR : Run Endpoint Script

Hello Everyone,

I have an issue with the action "Run Endpoint Script".

 

I want to trigger an executable file (.exe) through the "Run Endpoint Script" action from Cortex XDR. This executable is used to uninstall a specific software (It is not install

...

Error 1602 on install Cortex Agent

Hi! I have a problem with the installation of a Cortex Agent. 
I'm Installing version 8.2.0.46438 on a W2019 and W2016 Server, but in a few servers the install gets the attached message (i have a lot of other 2016/19 servers running OK).


Please if you

...

Resolved! XDR Usecase Creation | XDR Rule

We have 3 use cases for which we want to set up 3 rules in XDR, we would like to get your help to identify the best avenue to address them :

  • UC 1 : deploy a rule that DETECT a behavior or IOC (ex: failed auth, file with specific SHA1...), AND generat
...

Constant Cortex XDR Agent upgrades

Hello,

I am working in an organization with about 25,000 machines installed with Cortex XDR solution.
Recently we have noticed that there are many frequent upgrades being rolled out within a short time span.
To date, we are still having trouble keeping

...

TIbrahim by L0 Member
  • 1305 Views
  • 1 replies
  • 0 Likes

Resolved! XQL query for cloud assets

Dear community,

 

I've trying to build an XQL query to search for the cloud assets that does not have XDR agent install.

From the GUI, these data is available under the following 2 locations:

- Cloud Inventory --> Specific Cloud Assets --> Compute In

...

  • 2154 Posts
  • 83 Subscriptions
Top Liked Authors