Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 439 Views
  • 0 replies
  • 2 Likes

USB protection exeption for ClickShare usb Device

Hello everybody,

 

if we block USB Drives/Windows drives our ClickShare (USB Screen Share Dongle) devices also get blocked.

But they don´t appear in the "Device Control Violations" list so we can´t exclude them from blocking. 

We tried to exlude the

...

D.Meyer by L1 Bithead
  • 1519 Views
  • 8 replies
  • 0 Likes

Resolved! Basic questions to host firewall

Hello dear community, 

 

what is the correct setting for disabling the management of host firewall through Cortex XDR? Why do I wan't that? Because I need to get the windows firewall running through GPOs. Host firewall from PA Cortex is not suitable

...

RFeyertag_0-1735955355407.png
RFeyertag by L4 Transporter
  • 694 Views
  • 2 replies
  • 0 Likes

Directories CIEE x Cortex

dear, I have two directories in the cie, but in the cortex in the preset function it only brings the old one, not the newer one. How can I do it in Cortex so that it only brings information from the new directory?

Impossible uninstall Cortex XDR

Hello,

 

Because of my previous work, I had to install Cortex XDR to work remotely from home and access to the VPN.

Now that I'm no longer working for them, I would like to uninstall Cortex XDR from my laptop (MacBook Pro M2) but it is impossible. I

...

Rixals by L2 Linker
  • 2675 Views
  • 25 replies
  • 0 Likes

CVEs for applications Unsupported Platform

We have quite a bit of different softwares installed here, many Adobe products, 7-zip etc which I know have CVEs issued. Do I need to do something to enable this feature in XDR? ALL of the software detected shows Unsupported Platform. Does this featu

...

DopedWafer_0-1737557531926.png

Linux Agent Tampering protection

Hello Palo Alto Live Community,

 

I hope this post finds you well. I’m currently exploring the tamper protection capabilities of Cortex XDR for Linux and would appreciate insights from this knowledgeable community.

 

Specifically, I am interested in

...

XQL 2 Datasets

Hello community,

I am reaching out to you after many hours of trying to get this XQL query but something is not working.

I need to join the IP address from endpoints to my query 

dataset = management_auditing
| filter description contains "SOX" and (des

...

Disable notification in user agent

Hello,
I have an exception rule on a file that is being applied correctly. The file executes because of this exception, but in the user agent you get a warning that an unusual activity has been encountered or that a malicious activity has been encount

...

Agent stops because of full storage

Hi,

 

We recently encountered an issue where an XDR agent stopped functioning, and all protections were disabled (except for tamper protection) due to a full temp folder. Has anyone experienced a similar problem and identified the root cause or poten

...

paIoaItonetworks_1-1736243068553.png
  • 2217 Posts
  • 86 Subscriptions
Top Liked Authors