Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4404 Views
  • 0 replies
  • 3 Likes

SBAC limitations: Delegation of full control (profiles and exceptions) for a specific group of endpoints.

Hello community! I'm looking for the best way to delegate Cortex XDR administration to an IT team within a specific department. The goal is to give them full control over a particular group of endpoints, ensuring strict separation: they shouldn't have visibility into or the ability to manage the endpoints in the main network. The problem: I've b...

cyvrlpc.sys failure

Our IT department supports a OurDesktop virtual environment. I was notified of an error that has been coming up during multiple sessions. It acts somewhat like a BSOD in that it shows an error then reboots the computer for you. No configuration changes were made. Running v8.9 in this environment. Stop code: SYSTEM_SERVICE_EXCEPTION (0X3B) What...

Resolved! Configuration/Whitelistings accross mutliple Cortex Tenants

Hello everyoneI am working in an MSSP environment and managing several Cortex XDR tenants. While reviewing the official Palo Alto Networks documentation and online resources, I couldn’t find any information about whether it is possible to create configurations (such as exceptions, exclusions, custom detections likes BIOCs etc.) once and apply th...

MaaHaa by L0 Member
  • 1407 Views
  • 1 replies
  • 0 Likes

Issue with IOC not blocking MyPDFSwitch executable

Hello, I have been receiving alerts related to a file named MyPDFSwitch_8173674.exe, where the filename ends with random numbers. I created an IOC with the following pattern: MyPDFSwitch*.exe However, today I received another alert related to this file, so I suspect that the IOC is not working properly. Could you please advise what might be happ...

Cortex XDR Uninstall without password and active tenant

On Windows computer we have installed the cortex XDR agent on POC tenant.The tenant was deleted but we don't uninstalled the agent on the client computer.We try to uninstall it manually, but we don' have the password.We try with the default password, but we can't. Any idea to uninstall ? #Cortex #Cortex XDR #uninstall

LABRIC by L0 Member
  • 55578 Views
  • 8 replies
  • 0 Likes

Resolved! Up-to-date detections for TeamPCP malware used in Trivy and Checkmarx compromises available?

Hi, we're currently using the data collected via XDR and other sensors to hunt for IOCs of the recently observed attacks against aquasecurity Trivy Github actions, as well as Checkmarx KICS. This, obviously, focuses mainly on network-based IOCs like C2 domain and IPs, as well as file hashes and version strings in filenames.However, the attackers...

Enable access to required PANW resources Cortex

I would like to deploy an XDR For IP address ranges in Google Cloud Platform (GCP), refer to these lists for IP address coverage for your deployment: https://www.gstatic.com/ipranges/goog.json: IP address subnet ranges https://www.gstatic.com/ipranges/cloud.json: IP address ranges associated with your region Should I use all the IP addres...

KVishwan by L0 Member
  • 775 Views
  • 1 replies
  • 0 Likes

Adding dynamic groups to XQL output?

Looking to add the dynamic groups assigned to endpoints as a field in an XQL query. Here is what I have right now below. I'm unable to figure out if there is a way to get the dynamic group names in there. That would help us find machines easier than using the GUI method as this is a single report instead of trying to combine multiple exports due...

J.Suter by L2 Linker
  • 717 Views
  • 3 replies
  • 0 Likes

Inconsistent AnyDesk Detection in Cortex XDR

Hi everyone, I'm observing inconsistent detection behavior in Cortex XDR during weekly on-demand scans related to the AnyDesk application. On some endpoints, AnyDesk is detected as "Suspicious executable detected", while on others no alert is generated, even though the application is present. One common pattern we observed is that the alerts are...

Resolved! Try to install the Cortex MCP server

Hi all, I try to use "Cortex MCP server" for testing purposes. https://docs-cortex.paloaltonetworks.com/r/Cortex/Cortex-MCP-server/Install-the-Cortex-MCP-server I use a Docker installation on Windows 11. What I've done so far: - Created and copied the API URL, API key, and API key ID. - Downloaded and extracted the MCP zip file: - I c...

Screenshot 2026-03-20 112535.png
Screenshot 2026-03-20 103758.png
PeterMS by L1 Bithead
  • 2268 Views
  • 1 replies
  • 0 Likes

Resolved! E token Cortex XDR blocking

In our Organization E-Token is widely used by different departments/branches for specified purpose .However our cortex XDR is blocking the same under CD ROM category . How to allow the same and where to allow.

MEERSHAH by L0 Member
  • 951 Views
  • 1 replies
  • 0 Likes

Integrating VirusTotal with Cortex XDR

Hi Guys,In the Artifacts section we are not able to see the VT Score . For this we are manually copying the IP's , Hashes & viewing in the Virustotal console.Got to know we need to configure the API key but the concern is what data does Cortex XDR submit to VT ?only hashes , IP's or it will upload the entire file ?What are the precautions/be...

Resolved! PLease Correct the XQL query I have Created for the objective

Hi Community, I want to implement this objective so developed two queries with regex and non regex but it is giving tons of logs, can anyone help me on fine tuning or change the queries or correct them. Thank you Destructive Wipe / Anti‑Recovery Utilities Objective To detect destructive actions where adversaries attempt to wipe data or remo...

Resolved! Help me on developing XQL Query

Hi Community, Please help me on creating XQL query for cortex XSIAM on the below requirement. VPN Credential Abuse / Anomalous VPN Access Objective:Detect initial access via compromised VPN credentials, the primary entry vector used by Handala Hack. It looks for suspicious VPN authentication events such as first‑time logins from new geolocati...

  • 2614 Posts
  • 98 Subscriptions
Top Solution Authors
Top Liked Authors