Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4397 Views
  • 0 replies
  • 3 Likes

Resolved! How to update broker VM IP in the existing XDR agents ?

Hi All We have recently changed the region of our XDR tenant and we have migrated all of our Agents. now the issue is most of our agents were configured using cytool/CMD and support team configured the Broker VM IP manually. As the broker VM IP needs to be changed , i was wondering how to do that now? i didnt find any good documents related w...

Queries about different operating system and the hours of attention to incidents

Hello everyone, I am trying to create some XQL queries to create some dashboards but without success. I wanted to know if you could help me, the questions would be the following: 1. that the different operating systems are shown, but that it shows if the computer is W7, W11, WS2012, WS2016, Ubuntu, MAC, etc. There is a query but it only shows ...

Assistance Needed: Blocking URLs (Google Docs & Gmail, TeamViewer and others)

Dear Support Team, I am writing to request assistance with configuring a policy within in my version of Cortex XDR Pro. As part of the migration process, I need to restrict access to Google Docs and Gmail, TeamViewer and others to ensure the blocking. Any additional information or recommendations you can offer regarding this specific situation w...

Cortex XDR Scanning on Exchange and Sharepoint Servers

Hello, We are looking to add the XDR agent to our on-prem Exchange and Sharepoint servers, and I had two questions about the scanning capabilities of the agent on these servers. Does XDR scan emails and attachments that reside on Exchange servers? Does XDR scan files that are stored on Sharepoint? If an external user posts a document on our ...

ldonahue by L0 Member
  • 2038 Views
  • 1 replies
  • 0 Likes

Query to Monitor Computer Uptime

Hello, I intend to formulate a new query to retrieve the computer's uptime, and if the system has been active for more than 30 days, generate an alert. Although I attempted the following XQL Search, the outcome yielded no results: config case_sensitive = false | preset = xdr_event_log | filter event_type = EVENT_LOG and action_evtlog_even...

Cortex XDR agent and EICAR malware test file

Hi team, It feels like I'm missing something and so would appreciate of someone could explain to me why the XDR agent on Windows (latest 8.2.1 with block policy) is not reacting to EICAR malware test file (X5O!P%@AP[4PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H)? I tried malware scan on the file but the agent reported it clean. I fu...

stig_72 by L1 Bithead
  • 10286 Views
  • 2 replies
  • 0 Likes

Firefox Extensions

Hello guys, this is my first post, I'm glad I can be part of this community, I tried to make a query to see what extensions are installed in Firefox. I hope it is ok and useful and if you have something to add to improve it, I would be very happy. config case_sensitive = true | preset = xdr_file| filter agent_os_type = AGENT_OS_WINDOWS | filte...

SorinP by L0 Member
  • 1579 Views
  • 1 replies
  • 0 Likes

Resolved! Policy to block the access of Microsoft Store through Cortex XDR

Hello, i would like to know if there is a way to block access to microsoft store through Cortex XDR , i know there are many way to reach this goal such as GPO. but i would like to use Cortex XDR . because it will be harder to manage (remote) out of network users unlike cortex which can be forced almost instantly. any help will be highly appre...

Managing server Option Not Unavailable - Cortex XDR

I am attempting to change managing server option for an endpoint, however the option is unavailable when I go to endpoint control. See image below: I do have endpoint administrator privileges in Cortex XDR Management UI as shown below: The documentation indicates that I should have administration privileges to Cortex XDR in the Hub. I...

brownchris_1-1706110978705.png
brownchris_2-1706111104164.png
brownchris_3-1706111851861.png

Partial protected endpoints

Dears, In some cases Endpoint is going to Partial protected due to some issues. I have read this knowledge base. (https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004OGWCA2&lang=en_US%E2%80%A9) Now I want to know that How can I get alert about when endpoint goes Partial protected mode. I have checked agent logs. There...

  • 2611 Posts
  • 98 Subscriptions
Top Solution Authors
Top Liked Authors