Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Wildfire Test File

Has anyone had issues with the Wildfire Test file not showing up as an alert in the cloud? On the workstation it's getting blocked just fine. I haven't had a regular alert fire in about 2 months. Just wondering if I have an underlying communication i

...

Resolved! Symantec Uninstall or disable and Enable Cortex

All 

Thanks in advance for help 

 

We have Cortex in Report/Audit mode and Symantec Endpoint protect in block mode . We want to enable Cortex for Block mode and either disable or uninstall Symantec . 

Has anybody have got any advice or experience wit

...

Balaraju by L2 Linker
  • 2632 Views
  • 3 replies
  • 0 Likes

Resolved! Agent upgrade failure 5.0.11

Hello, 

 

I have issue to upgrade the affected version 5.0.11 to 5.0.12 on windows server 2008, when I install the msi  rollback to the last version. Is anyone has the same issue.

 

thanks 

elfayafi by L0 Member
  • 1596 Views
  • 2 replies
  • 0 Likes

Detect where a process has been killed

We have a scenario where users are able to kill a certain process to bypass security.

How can we leverage XDR to detect where the specific process name has been killed and, ideally, prevent it?

I thought maybe an IOC or BIOC but the IOC doesn't seem

...

SARowe_NZ by L3 Networker
  • 3061 Views
  • 3 replies
  • 0 Likes
  • 2078 Posts
  • 82 Subscriptions
Top Solution Authors
Top Liked Authors