Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4323 Views
  • 0 replies
  • 3 Likes

Resolved! XQL Help - Count array values

Hello,XQL beginner here, after 1 hour of tryhard with the cheap xql palo alto documentation. Finally got what I want but I feel like I've done it the wrong wa Context I have a BIOC rule monitoring for read on multiple folders that can contains identical files. Target The list of the top file that have been read Example Monitored file pa...

Resolved! Not able to uninstall 7.3.0 version

Hello, I have a PC with Cortex XDR version 7.3.0 and I can't uninstall it. I've already tried the Cytool protect disable command but it doesn't work. I've also tried XDRAgentCleaner 7.6.0 but obviously it doesn't work, it doesn't accept the admin password in any case. Does anyone have a solution? Thanks

Resolved! Cortex XDR _USB Blocking Levels

Hello, Please let me understand the levels of usb blocking in the edr policy. If the access is blocked does it allow printers, Charging smartphones, Other utilities like Cameras etc. Thanks in advance.

XDR Endpoint Visibility Dashboard

Hello, Let's assume I have 5 departments inside my organization. Each contains 6-7 endpoints. I want to create 5 dashbaords for each. In these dashboards, I want to see only organization specific endpoints ( 6-7 endpoints would be in each dashboard). I want to see incidents only related to specific organization. PS: I can filter endpoints accor...

How to install Cortex XDR Agent as Golden image using Debian package for Linux

I'd like to install the Cortex XDR agent as a golden image using a Debian file on Ubuntu. I tried to execute the command "apt-get install ./cortex-8.2.1.120305.deb -- --vm-template" or "apt-get install cortex-8.2.1.120305 -- --vm-template", but it doesn't work. Can someone help or suggest to me how to install an agent as Golden Image for Ubuntu?

DTRH: Finding New XQL Fields and Joining Data

DTRH: Finding New XQL Fields and Joining Data I was trying to look at some user login information through XQL and I started poking around the different fields that were being returned. I began one of the user login sample queries available in the query library and made a few small tweaks to de duplicate all the logins just so I could get a list ...

JEbrahimi_0-1618590705273.png
JEbrahimi_1-1618590705280.png
JEbrahimi_2-1618590705285.png
JEbrahimi_3-1618590705288.png

Host Firewall API

Has anyone had any luck adding IPs to the XDR host firewall via API? It seems like this would be a great function to have. (Looking at you Palo Alto DEVs) I've also looked at: Adding IPs to an IOC - but IOCs cannot be added to custom blocking rules in a policy https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR-REST-API/Rule-Management I'v...

CJNTS by L2 Linker
  • 2263 Views
  • 3 replies
  • 2 Likes

How to allow hash for specific endpoint on allow list

There is an option in the hash to define an action-allow list, but it allows the hash for all the endpoints. We need to allow hash for specific endpoints, but we don't want to create a policy and profile for each and every time. Is there a way to allow a hash for a specific user, as shown in the image below, without creating a profile and policy?

RajeshPremSingh_0-1682321575543.png

Resolved! How to update broker VM IP in the existing XDR agents ?

Hi All We have recently changed the region of our XDR tenant and we have migrated all of our Agents. now the issue is most of our agents were configured using cytool/CMD and support team configured the Broker VM IP manually. As the broker VM IP needs to be changed , i was wondering how to do that now? i didnt find any good documents related w...

Queries about different operating system and the hours of attention to incidents

Hello everyone, I am trying to create some XQL queries to create some dashboards but without success. I wanted to know if you could help me, the questions would be the following: 1. that the different operating systems are shown, but that it shows if the computer is W7, W11, WS2012, WS2016, Ubuntu, MAC, etc. There is a query but it only shows ...

Assistance Needed: Blocking URLs (Google Docs & Gmail, TeamViewer and others)

Dear Support Team, I am writing to request assistance with configuring a policy within in my version of Cortex XDR Pro. As part of the migration process, I need to restrict access to Google Docs and Gmail, TeamViewer and others to ensure the blocking. Any additional information or recommendations you can offer regarding this specific situation w...

Cortex XDR Scanning on Exchange and Sharepoint Servers

Hello, We are looking to add the XDR agent to our on-prem Exchange and Sharepoint servers, and I had two questions about the scanning capabilities of the agent on these servers. Does XDR scan emails and attachments that reside on Exchange servers? Does XDR scan files that are stored on Sharepoint? If an external user posts a document on our ...

ldonahue by L0 Member
  • 1974 Views
  • 1 replies
  • 0 Likes
  • 2590 Posts
  • 97 Subscriptions
Top Solution Authors