Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4320 Views
  • 0 replies
  • 3 Likes

Resolved! Suspicious domain suffix with a rare user agent - Explanation

Hello Community,The BIOC Analytics has recently added these alerts and I wanted to get some insight and I hope this thread can be used in the future by others as well. While the same seems straightforward there are some issues. The name of the alert suggests that a suspicious domain suffix was seen WITH a rare user agent. The issue is that in ...

Agent Audit Log "Start" event

Hi, I cannot find a single "Start" event under my Agent Audit Logs. If I can see there is a "Start" if I use "Sub-Type" as a filter so I suppose there must be "Start" event. Does anyone have idea?

Huge Cortex XDR upload traffic observed from firewall

We have branch network connected to Data center via MPLS VPN link. All branch PCs internet traffic going out from the DC firewall. From all the branch PCs (Around 8000), we have observed a huge outbound traffic towards internet related to Cortex XDR traffic. Has anyone observed this similar behavior from Cortex XDR agents? I have attached an scr...

DS1465_0-1718690466240.png
DS1465 by L1 Bithead
  • 1291 Views
  • 1 replies
  • 0 Likes

API Syntax Issue

Hi everyone, I'm trying to use the 'run_script' API to start the built-in 'Execute_Commands' script on a target machine. I've worked through a few error messages already regarding the command string having black slashes, timeout not being set as integer etc. Now Cortex is telling me I'm missing some parameters from the API call. I have no idea...

Required Windows Event IDs for the best Cortex XDR detection performance

Hello, dear Community, I need a list of Windows event IDs required for BIOC and other Cortex XDR rules to work effectively. For example, when we performed a Kerberos user enumeration attack using Kerbrute, it was not detected initially. Cortex XDR requires event ID 4768 to be enabled to detect such an attack. After enabling this event ID and t...

agsaqqal by L0 Member
  • 2581 Views
  • 1 replies
  • 2 Likes

Resolved! Email_data dataset empty

Hi all, have been digging into our Cortex tenant and noticed that the email_data dataset has no data. Our emails come from Microsoft Exchange online. To get data to this dataset is it just having a compliance mailbox set up in exchange? We already have a connector to M365 and I can see data in the dataset msft_o365_exchange_online_raw but we hav...

Allowing child process from parent process in Cortex XDR

Hello, Is there a way to allow a legitimate parent process to create a legitimate child process on Cortex XDR that is being blocked due to "Suspicious Process Creation"? In my case, I whitelisted the child process but the block continues. I do not want to whitelist the parent process as this may allow malware into our environment someday. I reme...

oburgos by L0 Member
  • 11409 Views
  • 4 replies
  • 0 Likes

Resolved! Notification when alerts/Incident is resolved

Hi CommunityI am trying to get notifications when alerts or incidents are resolved but it doesnt seem that there is a direct way to do so.So is there a way to send a notification (Syslog or Email) when an alert or an incident is resolved?Thanks in advance.

Belhaj_a by L1 Bithead
  • 2399 Views
  • 2 replies
  • 0 Likes

Resolved! Automatic review of Cortex XDR for Prevention Profile: Agent Settings, Malware and Exploit

Hello Together I would like to automatically review the settings in the Cortex XDR Prevention Profile: "Agent Settings", "Malware" and "Exploit". As example that in the Agent settings, the Disk Space Quota should be set between 5000 and 2000 MB or that the Uninstall PW is Defined ... Are there ways to automate this process? As an example, I ...

MikeDups by L0 Member
  • 2069 Views
  • 1 replies
  • 0 Likes

Multiple Paths in Disable Prevention Rules

HelloIs it possible to specify multiple values while creating prevention rules exception for one "application" ? If so what is the schematics of adding those ?Especially in path section. As if application has multiple location paths for its different modules such as C:\program files (x86)\ or %program data% or C:\program files\ etc where wild ca...

  • 2585 Posts
  • 95 Subscriptions
Top Solution Authors