Cytool firewall show - log save
Does anyone know if it's possible to automatically save the output of the 'cytool firewall show' command to a text file?
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.
Does anyone know if it's possible to automatically save the output of the 'cytool firewall show' command to a text file?
Hi everyone
Is there a possible way to assign an endpoint tag during agent installation on Kubernetes with YAML installer?
The PANW documentation about Kubernetes agent is very poor.
Thanks & best regards
Hello, we are using Cortex in a Citrix VDI environment.... Non-persistent VDI.
We installed the agent with the VDI flag on the GoldenImage.
When we perform the imageprep scan, it timeout and on cmd appears to be stuck on this file:
\\?\GLOBALROOT\Dev
...
Hello, is it possible to set a temporary exception in "Allow list"?
When you want to make an exception but for a limited time; until an identified date.
Once this date has passed, the rule would be automatically deactivated...
a random dir /a on a VM that seemed to be struggling produced a list of unexpected files:
07/09/2023 09:28 PM 20,000 ZZZZZ2852017353.doc
07/21/2023 10:10 PM 50,240 !!!!!2729304900.doc
07/21/2023 09:34 PM 3,000,000 XOR
...
Hello everyone,
I need to get BIOC IOC numbers from XDR tenants. I am trying to create a horizantal bar widget on xsoar like below. Is there any way to get those numbers? Thanks in advance
Hello dear LIVEcommunity!
someone know if Cortex XDR pro cover this attack?
RDPStrealer is a stealer that allows attackers to obtain the user's login credentials when trying to contact other machines, thus ensuring their persistence on the network b
Dear LIVEcommunity,
I was looking to restrict the firewall rule by only whitelist a certain ip address to reach the syslog server sitting in DMZ.
Cortex XDR is one of application that I need to whitelist so that the syslog messages can reach the sy
...
I have fully configured the Broker VM and activated the Local Agent Settings APP (everything is green and working). The Broker VM appears in the drop down in section Download Source in Agent Settings Profile (that I am editing), BUT it is grayed out
...
Hello dear LIVEcommunity!
Should we follow the recommendation from microsoft or does cortex xdr pro cover this CVE?
https://www.microsoft.com/en-us/security/blog/2023/07/11/storm-0978-attacks-reveal-financial-and-espionage-motives/
BR
Rob
We are using Coretex Paloalto XDR. From yesterday, in one of our application servers, the web.config file automatically disappears. We checked the incedent logs in XDR but no incedent or log found. it happened twice from yesterday .
Regards
Ram
Hi Team,
As per the XDR Compatibility list, RHEL 10 is not mentioned in the list. Can someone confirm if it is compatible?
Regards,
Shahwaz
Hello there,
As the title suggests, we are looking for a test we can simulate the behavior (have kali / attacker / victim test environment).
Any suggestions?
Thanks
CRITICAL - Linux version of Abyss Locker ransomware targets VMware ESXi servers
Links for more information:
https://www.bleepingcomputer.com/news/security/linux-version-of-abyss-locker-ransomware-targets-vmware-esxi-servers/
https://researchsnipers
...
Hi,
Is it possible to obtain a custom widget like "Vulnerabilities On All Endpoints Over Time" via XQL?
We would like to filter out some endpoint
Is there a dataset with detailed history information?
Thanks
Subject | Likes |
---|---|
4 Likes | |
3 Likes | |
2 Likes | |
2 Likes | |
1 Like |
User | Likes Count |
---|---|
8 | |
4 | |
3 | |
3 | |
3 |