Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4397 Views
  • 0 replies
  • 3 Likes

XQL query for browsers installed or in usage on host + Host_name.

Hi,I need to find which browsers the users using for daily tasks.I'm looking for a XQL query for browsers installed or browsers in usage by the user + hostname,The date that the app installed and the version is not so important as long as i get the browser name or vendor like chrome, Firefox etc.I can provide browsers list to search for or any o...

XDR Agent Stop 8.3.0

Hi, I would like to know if anyone has experienced this problem. Sometimes, without any apparent reason, the Cortex XDR Agent version 8.3.0 stops responding on Windows Server 2016 servers. When we check the services, the service is stopped We restart it, force the communication, and everything works fine.Sometimes, we need reboot server to start...

tlmarques by L4 Transporter
  • 1920 Views
  • 2 replies
  • 0 Likes

Panorama integration

Hello, Have anybody integrate with Panorma? There is an option to do so under the NGFW integration: How exactly does it work? I have integrated XDR with NGFW and everything works fine, logs are collected, but I am wondering what is the use case to integrate with Panorama.

xdrxdrxdr_0-1711041502188.png

Resolved! Find the responsible application in Windows for making malicious DNS requests

Hello everybody, I sometimes receive alerts from our firewall blocking a malicious DNS request, but when I want to track it to the application that made that request, I just see Windows DNS cache service. Is there any way to audit specific DNS requests e.g. "gyoutube.com" ,which is actually malicious, in a Windows client using Cortex or other to...

Cortex XDR is unable to block USB viruses - the reason is unknown.

We recently encountered an issue where a user's computer got infected with a USB virus after inserting a USB drive. The virus uses USB Driver.exe to create some directories and malicious programs as shown in the attached image. Additionally, it uses vmnet.exe to load these DLL files. However, Cortex XDR did not block it. We have already enabled ...

kentwuhc by L1 Bithead
  • 2108 Views
  • 1 replies
  • 0 Likes

Virtual functions/Variables - Creating anomaly based detection rules - XQL

Hello Everyone, Cortex XDR has the functionality does allows you to use XQL queries to create lookups or datasets. The problem is that these are static and cannot be dynamically updated for detection rules.The use case I had in mind is that I have two XQL queries the first one looks at events occurring from 30 to 1 day ago. The second query lo...

Resolved! Suspicious domain suffix with a rare user agent - Explanation

Hello Community,The BIOC Analytics has recently added these alerts and I wanted to get some insight and I hope this thread can be used in the future by others as well. While the same seems straightforward there are some issues. The name of the alert suggests that a suspicious domain suffix was seen WITH a rare user agent. The issue is that in ...

Agent Audit Log "Start" event

Hi, I cannot find a single "Start" event under my Agent Audit Logs. If I can see there is a "Start" if I use "Sub-Type" as a filter so I suppose there must be "Start" event. Does anyone have idea?

  • 2610 Posts
  • 98 Subscriptions
Top Solution Authors