Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4430 Views
  • 0 replies
  • 3 Likes

Resolved! Up-to-date detections for TeamPCP malware used in Trivy and Checkmarx compromises available?

Hi, we're currently using the data collected via XDR and other sensors to hunt for IOCs of the recently observed attacks against aquasecurity Trivy Github actions, as well as Checkmarx KICS. This, obviously, focuses mainly on network-based IOCs like C2 domain and IPs, as well as file hashes and version strings in filenames.However, the attackers...

Enable access to required PANW resources Cortex

I would like to deploy an XDR For IP address ranges in Google Cloud Platform (GCP), refer to these lists for IP address coverage for your deployment: https://www.gstatic.com/ipranges/goog.json: IP address subnet ranges https://www.gstatic.com/ipranges/cloud.json: IP address ranges associated with your region Should I use all the IP addres...

KVishwan by L0 Member
  • 857 Views
  • 1 replies
  • 0 Likes

Adding dynamic groups to XQL output?

Looking to add the dynamic groups assigned to endpoints as a field in an XQL query. Here is what I have right now below. I'm unable to figure out if there is a way to get the dynamic group names in there. That would help us find machines easier than using the GUI method as this is a single report instead of trying to combine multiple exports due...

J.Suter by L2 Linker
  • 740 Views
  • 3 replies
  • 0 Likes

Inconsistent AnyDesk Detection in Cortex XDR

Hi everyone, I'm observing inconsistent detection behavior in Cortex XDR during weekly on-demand scans related to the AnyDesk application. On some endpoints, AnyDesk is detected as "Suspicious executable detected", while on others no alert is generated, even though the application is present. One common pattern we observed is that the alerts are...

Resolved! Try to install the Cortex MCP server

Hi all, I try to use "Cortex MCP server" for testing purposes. https://docs-cortex.paloaltonetworks.com/r/Cortex/Cortex-MCP-server/Install-the-Cortex-MCP-server I use a Docker installation on Windows 11. What I've done so far: - Created and copied the API URL, API key, and API key ID. - Downloaded and extracted the MCP zip file: - I c...

Screenshot 2026-03-20 112535.png
Screenshot 2026-03-20 103758.png
PeterMS by L1 Bithead
  • 2345 Views
  • 1 replies
  • 0 Likes

Resolved! E token Cortex XDR blocking

In our Organization E-Token is widely used by different departments/branches for specified purpose .However our cortex XDR is blocking the same under CD ROM category . How to allow the same and where to allow.

MEERSHAH by L0 Member
  • 1020 Views
  • 1 replies
  • 0 Likes

Integrating VirusTotal with Cortex XDR

Hi Guys,In the Artifacts section we are not able to see the VT Score . For this we are manually copying the IP's , Hashes & viewing in the Virustotal console.Got to know we need to configure the API key but the concern is what data does Cortex XDR submit to VT ?only hashes , IP's or it will upload the entire file ?What are the precautions/be...

Resolved! PLease Correct the XQL query I have Created for the objective

Hi Community, I want to implement this objective so developed two queries with regex and non regex but it is giving tons of logs, can anyone help me on fine tuning or change the queries or correct them. Thank you Destructive Wipe / Anti‑Recovery Utilities Objective To detect destructive actions where adversaries attempt to wipe data or remo...

Resolved! Help me on developing XQL Query

Hi Community, Please help me on creating XQL query for cortex XSIAM on the below requirement. VPN Credential Abuse / Anomalous VPN Access Objective:Detect initial access via compromised VPN credentials, the primary entry vector used by Handala Hack. It looks for suspicious VPN authentication events such as first‑time logins from new geolocati...

Resolved! Please help me on developing xql query for cortex xsiam

Hi Community, Please help me on developing the xql query for cortex xsiam on the below objective. RDP Lateral Movement Burst Objective Detect high‑velocity RDP lateral movement, It detects multiple RDP connections (logon type 7/10) from the same account within short time spans, lateral movement to multiple hosts, and privilege misuse associat...

Resolved! Windows Event Collector vs XDR collector

Hello guru, it seems both served the same purpose to me. all i would like to ingest the event logs for analystic purpose. except the configuration nature, like WEC required AD config and XDR collector need an agent installed. what is the pros and cons for for WEC and XDR collector? any use case for each? thanks SdG

Resolved! host-insights apps refresh

Hi everyone, quick question. In my company we had several PCs with old versions of Notepad++ installed, and I created a script to remove them all via Cortex XDR . Meanwhile, the team started installing the correct version via Microsoft System Center Configuration Manager (SCCM). The question is: in the host-insights/apps some machines still ap...

tlmarques by L4 Transporter
  • 1710 Views
  • 1 replies
  • 0 Likes

Resolved! Cortex Assets Report without agent installed

Hi everyone, I'm working on a security visibility project and would like to leverage the Asset Inventory module to generate a detailed report of all Windows machines that do not yet have the Cortex XDR agent installed. The main goal is to use that data as the source for a dashboard widget. I'm new to XQL and have been trying to build a query wit...

  • 2623 Posts
  • 98 Subscriptions
Top Solution Authors
Top Liked Authors