Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4363 Views
  • 0 replies
  • 3 Likes

Resolved! Help me on developing XQL Query

Hi Community, Please help me on creating XQL query for cortex XSIAM on the below requirement. VPN Credential Abuse / Anomalous VPN Access Objective:Detect initial access via compromised VPN credentials, the primary entry vector used by Handala Hack. It looks for suspicious VPN authentication events such as first‑time logins from new geolocati...

Resolved! Please help me on developing xql query for cortex xsiam

Hi Community, Please help me on developing the xql query for cortex xsiam on the below objective. RDP Lateral Movement Burst Objective Detect high‑velocity RDP lateral movement, It detects multiple RDP connections (logon type 7/10) from the same account within short time spans, lateral movement to multiple hosts, and privilege misuse associat...

Resolved! Windows Event Collector vs XDR collector

Hello guru, it seems both served the same purpose to me. all i would like to ingest the event logs for analystic purpose. except the configuration nature, like WEC required AD config and XDR collector need an agent installed. what is the pros and cons for for WEC and XDR collector? any use case for each? thanks SdG

Resolved! host-insights apps refresh

Hi everyone, quick question. In my company we had several PCs with old versions of Notepad++ installed, and I created a script to remove them all via Cortex XDR . Meanwhile, the team started installing the correct version via Microsoft System Center Configuration Manager (SCCM). The question is: in the host-insights/apps some machines still ap...

tlmarques by L4 Transporter
  • 1427 Views
  • 1 replies
  • 0 Likes

Resolved! Cortex Assets Report without agent installed

Hi everyone, I'm working on a security visibility project and would like to leverage the Asset Inventory module to generate a detailed report of all Windows machines that do not yet have the Cortex XDR agent installed. The main goal is to use that data as the source for a dashboard widget. I'm new to XQL and have been trying to build a query wit...

Resolved! Basic Doubt - Analytics

Hello everyone, I’m configuring some features in Cortex and noticed that a few alerts are being generated by the Analytic Rules. How can I automatically create a CASE based on these alerts? My intention is to open incidents (i.e., “Cases”) in the console.This is meant to improve visibility and ensure proper alert monitoring.

Resolved! Request: XQL query for filename + optional hash logic (single stream)

Hi all,Could someone help me write an XQL query in Cortex XSIAM that: Detects process executions and file create/modify touches matching these names:svc.exe, pwrautomate.exe, mcs.bat, cleanup.bat, uri.bat, p.zip Also matches this masquerade regex (case-insensitive):^filters_update_.*_at_abdata\.com\.exe$ Treats hash IOCs as optional (include wh...

Problem with Juniper Syslog

Hi, this is my first post and I need help. I am trying to connect the syslog of a Juniper ACX7024X to my Broker, but I cannot see any logs. The router is sending logs, but I cannot see anything from Cortex. I set it to raw format, auto-select, but nothing. I understand that everything is configured correctly on the router, although we trie...

Cortex Data Lake - Windows 11 Build & Enablement(?) Info

Windows 11 (and 10 presumably) has a series of numbers which, together, identify the build and patch level of the OS. This would be a combination of Version: Windows 11 and/or Build Number: 10.0.22631. The Patch Level (or Enablement Level) is shown by an additional 4 digit number at the end of the Build Number like Windows Build 10.0.22631.431...

XDR as "SIEM" (challenge for discussion)

I wanted to leave a challenge here for discussion in the group.Why not use XDR as if it were a SIEM, in order to analyze more events with better accuracy, and to create more correlation and data enrichment? I’m referring to an environment with:XDR, XSOAR, Palo Alto/Fortigate firewalls, Windows and Linux systems, and O365. For systems that don’t ...

tlmarques by L4 Transporter
  • 1099 Views
  • 1 replies
  • 0 Likes
  • 2602 Posts
  • 98 Subscriptions
Top Solution Authors