Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4392 Views
  • 0 replies
  • 3 Likes

Resolved! Cortex XDR Incident Management Report by tags

Hi all, I need to create an Incident Management Report by using specific tags. Is it possible? Maybe I can do it via XQL query? If not, do you have any suggestions on how can I create incident reports for different tags? (I don't want to export the incidents and create reports via Excel!!!:D) Best regards.

Need the details regarding Cortex XDR agent traffic to internet or broker VM

Hello Team,Please let me know how much 1 agent of Cortex XDR can send request to XDR cloud(internet) or broker vm send request to cloud in duration of 1 minutes of time.Need this information to understand about the Cortex XDR agent traffic towards cloud and count of request/connections per 1 minute. Cortex XDR #brokerVM

How to import a multiple hash value in block list

Hello , Is there any option available to upload multiple hash value in block list using CSV file. I had checked for cortex xdr import file hash exception however its really difficult to find out the filetype for each hash value. So is there any option to ignore this and add only hash irresp of file type.Cortex XDR

Agent Upgrade Failure

Hello Everyone, I'm having a problem when upgrading an agent, it just gives timeout. From what I can understand, both these systems are "the same" but CALPE doesn't upgrade... I saw that it could be from a problem with Windows Azure Code Signing KB5022661 but when I check with "test_acs" it doesn't give an error... Any help is appreciated!

JoaoMachado_0-1701189260769.png
JoaoMachado_1-1701189371094.png

Resolved! Iterating over an array in XQL

Is there a way in XQL to iterate over an array? Imagine there is an array of mail receivers i want to check if each one contains a specific keyword such as "@company.com" so that i know there's no receiver outside my organization. emails = ["user1@company.com", "user2@anothercompany.com"] - i want to detect the second email.

Resolved! Automation rules

Hi all! Still fairly new to Cortex XDR. Currently trying to make some sensible alert automation rules.I have a specifik alert that puzzles me. I get some "FTH/SSH client reads office files" alerts. I have a legitimate use case for this, so I want to automatically resolve these alerts for a particular set of hosts.But ... I am not able to create ...

Allan_Holdt_0-1700558668197.png
aholdt by L1 Bithead
  • 2546 Views
  • 2 replies
  • 1 Likes

Scaning files for malware

Is it possible to use Cortex XDR to analyse malicious Microsoft Office files, such as Word, Excel and PowerPoint documents? If I right click on Office file and choose Scan with Cortex XDR will Cortex check if that file is not used for delivering malware, including binary files, documents, scripts, archives a macros?

Sedlacek by L0 Member
  • 2184 Views
  • 2 replies
  • 0 Likes

Legacy Exceptions - Endpoint version compatibility

Hi, everybody, I plan to accept Legacy Exceptions générated from my profile based policies. Major part of the endpoints are running [CE] versions, prior to 7.9. All these versions are supported. Does anyone had problems when activating these Legacy Exceptions in regard of ther endpoint versions? Thank's a lot ! Cheers.

What happens to existing prevention profiles when enabling the "Host Insights" license?

Hello Does anybody know what happens to the configuration of existing prevention profiles when the "Host Insights" license is activated? The environment currently has several prevention profiles that have the "XDR Pro Endpoint capabilities" enabled. The settings for host insights will appear under that setting according to this deployment vid...

Automate Isolation Endpoint

Just wondering if there is somewhere in xdr to tell it to isolate an endpoint automatically if we get a critical/high/medium alert or confirmed malware/ransomware alert. I thought there was something in the profiles to change for active this function.

Resolved! Unable to install XDR agent in Window server 2019 and 2022

Hi I have issue installing Cortex XDR 8.2.0.45438 on both 2019 and 2022 Server. with error logs below: ExecServiceStartCA: Service: cyserver ExecServiceStartCA: Error 0x800705b4: Service failed transition to 4 state (current state 1) ExecServiceStartCA: Error 0x800705b4: Failed, retrying (attempt no. 1)... ExecServiceStartCA: Error 0x8...

  • 2611 Posts
  • 98 Subscriptions
Top Solution Authors
Top Liked Authors