JAVA Query for Cortex XDR
is it possible to create a query to detect a specific java injection process?
Regards,
Shashank
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.
is it possible to create a query to detect a specific java injection process?
Regards,
Shashank
Why does cortex XDR increase cpu usage ?
And after agent upgradation does cpu usuage increase?
what all other factors are there for high cpu utilization because of cortex xdr?
Hello dear community,
I'd like to make the Disk encryption visibility module visible to our trainee. How is it possible, I couln't find any possibility.
BR
Rob
Hey dear community,
Threat actors often rename apps. Like a.exe instead of anydesk.exe. But they do not change the versioninfo.
https://www.youtube.com/watch?v=oMAvSpq9fYY --> Minute 37
Is it possible to track this with cortex xdr pro?
BR
...
I want to know the XQL query or filters which helps in the analysis of alerts & to know the source of file where it is coming into our system.
For example- whether user downloaded the file from browser or someone sent through outlook, from portable d
...
Hi All
I am currently creating some parsing rules and I am using split to seperate the _raw_log field into its individual fields. After my initiail split I have one a field that starts with a comma, or multple commas, depending on the log. Does any
...
Hi,
someone please elaborate XDR P2P how happens and how xdr elect one peer agent in the LAN.
Hi Team,
Does Cortex XDR support URL filtering. We have a request to whitelist a URL on XDR in order for user to be able to access it.
Wondering if this is even possible by XDR or should be taken care at proxy level.
Thanks
Hello,
Is XDR compatible on Qualys virtual scanner appliance. It is a azure based Linux server.
Hi Team,
Who can change user role access for account admin ? Instance administrator does not have access to change it. #UserRole #CortexXDR
Regards,
Gokul K
Hello,
Can we change authetication options while logging in to cortex xdr?
While logging in first time on cortex XDR we selected google authenticator but mistakenly google authenticator app got deleted from phone and after re-installing it is una
...
Hi
How I create a new user in Cortex XDr and assign him the "Security Admin" role?
thx
Hey there,
I need some help with a query please.
I want a query that returns instances of two events, but ONLY when the events do NOT occur within 2 minutes of each other.
dataset = xdr_data
| filter (event_type = ENUM.PROCESS and event_sub_type =
Subject | Likes |
---|---|
5 Likes | |
4 Likes | |
3 Likes | |
3 Likes | |
1 Like |