Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4397 Views
  • 0 replies
  • 3 Likes

Resolved! Agent not communicating

Hello, If I ask, can you please answer to this question? The certificate used for decryption was installed as a trusted root CA certificate to ensure communication between the Cortex XDR Agent and Cortex XDR Management Console. What action needs to be taken if the administrator determines the Cortex XDR Agents are not communicating with the Cor...

Cortex XDR 3.9 Release Notes - UEFI protection module

I noticed that Cortex XDR 3.9 includes something called a "UEFI protection module". Here is the description from the release notes: "Cortex XDR has expanded its malware protection capabilities by adding the UEFI protection module, which reinforces and provides coverage against pre-boot attacks." Source We've had some compatibility issues in ...

dbherol by L0 Member
  • 2040 Views
  • 1 replies
  • 0 Likes

Cortex XDR agent error 307

Hi all, I have an issue that started popping up with an agent installation - newly installed agents throw out a 307 error. the package is present on the xdr management console, and we are beneath the license limit. What can be the issue here?

Scan endpoint error

Hi, I need help, I have Cortex XDR policy to allow scans on the endpoint, however users are unable to start the scans, the option does not appear I can only scan, with cmd as administrator (cytool scan start) , in the GUI I can't even do it as administrator: my configuration:

tlmarques_0-1706887670317.png
tlmarques_1-1706887790216.png
tlmarques by L4 Transporter
  • 1724 Views
  • 2 replies
  • 0 Likes

Resolved! XQL - Process Tree Analysis - Join Statements

Hello,I am currently trying to create a five depth process tree to perform long tail analysis on it.The query in KQL language can be found here The moment I perform the first join statement everything breaksHere is the almost complete code but you can just test the first join. dataset = xdr_data | filter event_type = ENUM.PROCESS | fields agen...

Cortex XDR Local Analysis Worker high memory usage.

Hi, After upgrading Cortex XDR agent to version 8.2.1.47908 , one of our servers suffer massive memory usage by multiple Cortex XDR Local Analysis Worker processes (8x2GB=16GB RAM). After restarting the Cortex agent, memory is freed for a while, but the problem comes back again. The server is Windows Server 2016 (10.0.14393) – could you help me...

BrokerVM HA cluster

Hi team, I created cluster from scratch and added here 2 brokervm, then for new cluster I assigned dedicated IP address and FQDN, then in local DNS is created A record using ha cluster FQDN and dedicated IP address. Is ti true way? because I tried to install cortex xdr agent to endpoint using HA cluster IP as proxy list but no connection estab...

Sadig by L0 Member
  • 1740 Views
  • 3 replies
  • 0 Likes

Resolved! Command line to set a Proxy_List to an already installed Cortex XDR Agent

Hi. Does anyone know if there is a command line to set a proxy to an already installed version of Cortex XDR? I know the proxy can be set using the command line: Cortex_Installer.msi proxy_list=”<proxy>:<port>” That being said, I didn’t find any way to change the defined proxy, once the installation is complete, except completely un...

Cortex XDR unable to uninstall

In Win 10 Pro 22H2 19045.3930, Cortex XDR agent unable to uninstall or upgrade in one user pc. Agent setup unable to find in control panel installed applications. Present agent version 8.2.0.46438. Worked on uninstalling from action response, endpoint etc no output.

Resolved! Managed Digital Signers Block List

Hello All- I am hoping this is a quick question as I did not find this in XDR documentation. It is my understanding that Palo manages a "trusted signers" list. Is there a way to leverage a similar list to automatically block the use/execution of digital signers that are unwanted? I know that a custom BIOC rule can be created but am wonderin...

Resolved! Impact on licences expiration #Cortex XDR

Hello My Cortex XDR licences expire in a few weeks I can't find the exact impact, I suppose that the new malware signature won't be updated but : - Will I be able to handle to connect to the console, to handle the agent - Will the agent still work? Cortex XDR Thanks !

  • 2610 Posts
  • 98 Subscriptions
Top Solution Authors