Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4322 Views
  • 0 replies
  • 3 Likes

Cortex XDR PoC: Monitoring Malicious Chrome Extensions

  PoC Lab: Monitoring Malicious Chrome Extensions By: @mfakhouri Executive Summary With the convenience Chrome extensions provide, such as ad blocking, enhanced web viewing, and improving user experiences, it is no surprise that malicious actors seek to leverage Web Store services to deliver malicious content. In recent times, strikingly...

CortexLogo.png
browsext-arc.PNG
ChromeDirName.PNG
testQuery.PNG
mfakhouri by L3 Networker
  • 15555 Views
  • 2 replies
  • 15 Likes

Resolved! Cortex XDR Pro / Browser extensions

Has anyone ever configured their environment to detect on unauthorized or unsupported browser extensions? Or conduct a threat hunt based on known facts? We've seen some slip through the cracks and I know Cortex doesn't natively detect abused or malicious extensions. Any XQL ideas out there perhaps?

CraigV123 by L3 Networker
  • 1314 Views
  • 2 replies
  • 0 Likes

Cortex XDR 8.9 Non-Persistent Citrix Servers and Cache Write Issue

Hello everyone, We have encountered and issue where the target servers do not get content updates. The citrix Windows servers reboot nightly with the golden image configurations but do not receive the latest content updates. At the same time, around noon we have to reboot the target servers due to write cache filling up to 100%. Have you enco...

Resolved! Windows Installer DB: Current agent installation is missing

I am currently experiencing an issue while attempting to upgrade agents in the Cortex XDR console. The upgrade process fails with the following error message: "Windows Installer DB: Current agent installation is missing." I attempted to clean the endpoint; however, the process was unsuccessful. I would like to ask if there is any alternative...

Email Notifications Setup

Good day, Please does anyone know how to setup email alerts for cloud agents warning (like the notifications on the notification tab on the UI) and outdated agents (which are not the latest release/version). thanks

Reconnect after endpoint cleanup

Hello, I'm thinking about using the Endpoint Administration Cleanup tool. However, I wanted to be sure if an endpoint is mistakenly deleted would shows up again in our tenant (if connected in the next 90 days). Did anyone has experienced it yet? Is this supposed to be the same if an endpoint is in "Connection Lost" then is connected?If so, i...

Create a IOC without incident

Good morning, Today I would like to create a block for two malicious files that I found in our environment. I noticed that I can create an IOC to block paths, file names, IPs, etc. I have already created an IOC using a wildcard for the file name: PDFEditor_*.exe, but I would also like to block the process without generating an incident. Is that ...

Resolved! XDR add more values to incident classification

Hi everyone, When I close each incident, I need to add the CSIRT taxonomy flags (from the ENISA Reference Incident Classification Taxonomy: https://www.enisa.europa.eu/publications/reference-incident-classification-taxonomy) to the Cortex XDR case. Does anyone know if that is possible?

tlmarques by L4 Transporter
  • 1155 Views
  • 4 replies
  • 0 Likes

Inquiry regarding Tenant Backu & Recovery

I am looking for detailed information regarding the backup and recovery lifecycle for a Cortex XDR tenant. Specifically, I have the following questions: Automated Backups: Does Palo Alto Networks perform regular backups of tenant-specific configurations (Security Policies, Profiles, XQL queries, etc.)? If so, what is the standard frequency? ...

R.Abdeen by L0 Member
  • 474 Views
  • 1 replies
  • 0 Likes

Cortex Management Report

I want to know if I can generate a report of Cortex's actions over the last year or 3 months, such as what he blocked, quarantined, isolated, etc., but in a graph format. I tried using a widget library, but I can't find a way to represent that action. What can I do?

XDR 5.0 - opinion

Cortex Cortex XDR 5.0 tenant. What's your opinion https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-5.x-Release-Notes/Release-Information

tlmarques_0-1770656806817.png
tlmarques by L4 Transporter
  • 1380 Views
  • 8 replies
  • 0 Likes

Resolved! High Bandwidth on Broker VM: Cluster Mismatch (v29 vs v28) & P2P

Hi everyone, I'm facing high bandwidth usage on my Primary Broker VM. I need to validate if my diagnosis is correct: The Setup: Cluster: HA Pair. Node 1 is v29.0.77 (Healthy). Node 2 is v28.0.99 (Service "Local Agent Settings" is Red/Down). Policy: Download Source = Broker VM (P2P is currently disabled). My Questions: Cluster: Does the v...

Resolved! Correlating a file path to application inventory

Hello, I am gathering an application inventory for endpoints in our environment. As part of this inventory, I'd like to include the install path for these applications. Currently Host Inventory XQL dataset only showcases uninstall strings in the applications field. Assistance in correlating an install path via joining datasets or something si...

  • 2587 Posts
  • 95 Subscriptions
Top Solution Authors