Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4483 Views
  • 0 replies
  • 3 Likes

Resolved! XDR add more values to incident classification

Hi everyone, When I close each incident, I need to add the CSIRT taxonomy flags (from the ENISA Reference Incident Classification Taxonomy: https://www.enisa.europa.eu/publications/reference-incident-classification-taxonomy) to the Cortex XDR case. Does anyone know if that is possible?

tlmarques by L4 Transporter
  • 1558 Views
  • 4 replies
  • 0 Likes

Inquiry regarding Tenant Backu & Recovery

I am looking for detailed information regarding the backup and recovery lifecycle for a Cortex XDR tenant. Specifically, I have the following questions: Automated Backups: Does Palo Alto Networks perform regular backups of tenant-specific configurations (Security Policies, Profiles, XQL queries, etc.)? If so, what is the standard frequency? ...

R.Abdeen by L0 Member
  • 799 Views
  • 1 replies
  • 0 Likes

Resolved! Cortex Management Report

I want to know if I can generate a report of Cortex's actions over the last year or 3 months, such as what he blocked, quarantined, isolated, etc., but in a graph format. I tried using a widget library, but I can't find a way to represent that action. What can I do?

XDR 5.0 - opinion

Cortex Cortex XDR 5.0 tenant. What's your opinion https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-5.x-Release-Notes/Release-Information

tlmarques_0-1770656806817.png
tlmarques by L4 Transporter
  • 2421 Views
  • 8 replies
  • 0 Likes

Resolved! High Bandwidth on Broker VM: Cluster Mismatch (v29 vs v28) & P2P

Hi everyone, I'm facing high bandwidth usage on my Primary Broker VM. I need to validate if my diagnosis is correct: The Setup: Cluster: HA Pair. Node 1 is v29.0.77 (Healthy). Node 2 is v28.0.99 (Service "Local Agent Settings" is Red/Down). Policy: Download Source = Broker VM (P2P is currently disabled). My Questions: Cluster: Does the v...

Resolved! Correlating a file path to application inventory

Hello, I am gathering an application inventory for endpoints in our environment. As part of this inventory, I'd like to include the install path for these applications. Currently Host Inventory XQL dataset only showcases uninstall strings in the applications field. Assistance in correlating an install path via joining datasets or something si...

Resolved! Sending USB Alerts via syslog (Cortex XDR)

Hello, We have received a request asking whether it is possible for administrators to receive alert emails whenever a USB device is connected to any endpoints.(*Currently, the USB policy in Exploit – Device Configuration is set to Read Only.) (* I think the adminster wants to get the log [Inventory-Device Control Violations]) We attempted to c...

YSONG464633_0-1770612974843.png

Resolved! Microsoft Photos.exe

Hi, Does anyone experience receiving alerts from photos.exe due to "Suspicious File Modification" and the Module is "Anti-Ransomware Protection" even the program is legitimate?Other factors I'm seeing is due to possibly outdated version of the said program. *See attached reference photo*I'm hoping from anyone's advice from other members with the...

J.Indoc by L0 Member
  • 2259 Views
  • 2 replies
  • 0 Likes

Request for Query to Retrieve Endpoint Security Details.

Hi Team, I would like to create a query that provides the following information for endpoint security events: Severity Artifact type (e.g., executable files or other relevant artifacts) Endpoint name IP address Windows OS version Action taken (e.g., Block or Alert) Cortex Agent versionTimeframe: I will be set manually Cortex XDR ...

Brew package manager for MacOS

We utilise Brew for package manager for our Mac in our organisation and we have over 100+ engineers using it to manage their operating environment. Cortex doesnt pick up any of the applications installed via brew or any of the vulnerabilities associated with them and only detects anything once its in a running state. This seems like a very basic...

Vulnerability assessment report

Hello, In viewing this report I've noticed its still flagging servers that have been patched already and wondering how often that checks against all endpoints? I can go on a server and its not showing any updates needed and then look in the report and its in there showing it needs 68 updates which all come from a cumulative update (windows) but ...

Notepad++ block specific hash version

Guys, Does anyone know if it is possible to block the hashes associated with older versions of Notepad++? My goal is to allow only Notepad++ version 8.9.1 to be executed, and to block the installation and execution of all other versions.

tlmarques by L4 Transporter
  • 2202 Views
  • 3 replies
  • 0 Likes
  • 2632 Posts
  • 99 Subscriptions