Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Check Cortex XDR Agent status

Is it still possible to check the status of Cortex agent in registry? I want to check the status on the client side periodically. I know it is possible via cytool but i need to do this periodically on a lot of computers.

I know there was a way on Tra

...

Nazlikul by L1 Bithead
  • 2075 Views
  • 4 replies
  • 0 Likes

Cortex XDR Block List isolating machines

Hi all,

 

I'm running into this issue where some personnel do not want to add malicious hashes to the XDR block list as it will isolate the machine. As far as I can tell, adding a hash to the block list will only remove the file on execution or scan,

...

Resolved! Problem bei Installation eines Cortex XDR Clients 8.0.1.33809 (Win, 64 Bit, msi) auf Microsoft Surface Pro 9 5G ,Prozessor: Microsoft SQ3 (ARM64)

Wir haben Probleme bei der Installation eines Cortex XDR Clients 8.0.1.33809 (Win, 64 Bit, msi) auf einem Rechner Microsoft Surface Pro 9 5G (Prozessor: Microsoft SQ3 (ARM64) / OS: Windows 11 22H2)

Installation des Cortex beginnt,  Cortex-Installatio

...

Cortex XDR -Large upload Alerts

Hey folks,
Recently we are getting high number of large data upload alerts in Cortex XDR.
The issue is data upload alerts are flagged with domain name stun.l.google.com on port 19302 ,UDP.

Why browsers are connecting to this stun server ?
when queried a

...

Verifying Installed Modules

Hey Folks,

 

Just wanted to understand how can we verify on console and XDR agents console that agent are installed with EPP modules enabled?

 

Regards,

M.R.

Cortex XDR Cortex XSIAM 

Possible Values for event_types

Hello Community, 

 

I am trying to understand Palo Alto XDR logs fetched using API(XQL Query). 

I am using dataset as xdr_data, want to know what all event_types can come under this dataset. 

For ex: EVENT_LOG. 

What are the possible values we can ge

...

agent intall exceed license number of agents

I read the relevant documents, but I don't quite understand them. I hope someone can confirm them for me.

reference articale url :https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-overview/cortex-xdr-licenses/cortex-x

...

Felixcao by L3 Networker
  • 5058 Views
  • 5 replies
  • 0 Likes

Resolved! Threat ID #9999' generated by PAN NGFW

Hello,

 

I have turned off alerts on NGFW for Private URL, but I still get threat ID #9999. 

 

Can somebody a little bit more explain what this threat ID means? I am trying to clean it up, but still get these alerts.

And it is not any kind of malicious tr

...

LukasB by L2 Linker
  • 11446 Views
  • 5 replies
  • 0 Likes

Searching for multiple hashes on cortex XDR

Does anyone know a way to search for multiple hashes on Cortex XDR?

file_search = existing_files does not allow any operators other than "=" for the sha values and you can't string multiple in a query. 

I feel like I'm missing something and there sho

...

rufat87 by L1 Bithead
  • 2716 Views
  • 3 replies
  • 0 Likes
  • 2029 Posts
  • 81 Subscriptions
Top Solution Authors
Top Liked Authors