Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4322 Views
  • 0 replies
  • 3 Likes

Resolved! Push Cortex XDR datasets/logs to dedicated syslog server

Hi everyone,I’m looking for some guidance on whether it’s possible to forward Cortex datasets to a dedicated syslog server for long‑term retention. Has anyone successfully done this, or is there a recommended method?I’m also considering using Microsoft Sentinel as a destination, but I’m not sure if all Cortex datasets can be pushed there.Any ins...

Resolved! Installing Cortex Agent on Linux LXD

Hello everyone,I am looking to install the Cortex Agent on a Linux system within an LXD container. Does anyone have insights or a step-by-step guide on how to install the Cortex Agent in this environment?Additionally, is Cortex officially supported for installation on Linux LXD?Thank you,Amelia Cortex XDR

Cortex XDR installation on GKE AutoPilot cluster

Cortex XDR seems to support GKE AutoPilot in latest release 8.9. However, when generating the Kubernetes manifests on Cortex XDR dashboard, they will not deploy on AutoPilot cluster. Instead, error message is given after kubectl apply command:Violations details: {"[denied by autogke-default-linux-capabilities]":["linux capability 'SYS_ADMIN...

Pass-the-Ticket - PtT

Hi guys, I’d like to know if anyone already has a detection rule configured in XSIAM correlation for a Pass‑the‑Ticket attack.I’m building a rule from scratch, but it’s not as effective as I’d like. If anyone has a ready‑made rule or some solid ideas and can share them, it would greatly speed up the process.

XQL query to get a list of current applications installed on hosts

Hello everyone, Our team is trying to utilize the XDR host inventory dataset to gather details on what applications are installed on each host. We’re encountering an issue with Cortex XDR Host Inventory queries returning stale host data, which is producing duplicate host/application sets in our results. Is anyone aware of how we can resolve ...

Resolved! Exfiltration Simulation/Testing

I was wondering if anyone has good procedures or methodology for simulating various kinds of data exfiltrations. We have a handful of rules related to exfiltration but have not established a meaningful way of assuring they are functional and sufficient. Thanks!

M.Crow by L1 Bithead
  • 7861 Views
  • 3 replies
  • 0 Likes

KB KB5022661

Hello, Does anyone have a Cortex XDR query to check if any endpoints and/or servers are missing Microsoft KB5022661. Any assistance would be greatly appreciated

Unable to download a from from an endpoint - File size limit exceeded

Hello Cortex geeks, I have a problem with a large file on an endpoint. This file is relatively large (1.1GB), has no VT ranking as it's too large for it obviously, and Cortex alerted about it because of signature forgery. I want to download and examine the file to make sure, but Cortex does not allow downloading it. What is a good best practice ...

Resolved! File search query for Android

Does anyone know how to perform bulk queries in Cortex XDR for Android devices? I want it to show me all Android devices that contain a specific hash or that contain the same APK file.

Resolved! Android Cortex XDR

I want to know how to perform an XQL query for Android devices, where I search by hash and it shows me all the devices that have that .apk with that hash, or I can search by name.

  • 2589 Posts
  • 95 Subscriptions
Top Solution Authors