Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 590 Views
  • 0 replies
  • 2 Likes

Resolved! Agent script Library

Hello, 

 

I would like to know if a script to that invokes live terminal or other functions related to Cortex XDR can be done using agent script library.

NivedaR by L2 Linker
  • 2712 Views
  • 4 replies
  • 0 Likes

Resolved! Intense SSO failures

Hello everyone,

Recently after the update we started getting errors for SSO that say Intense SSO failures.
While investigating execution chain, I only ran into outcome reason as "Strong authentication is required or device authentication failed".
Is the

...

Linux operation mode (Pending)

Dear All,

I wanted to create a widget to display the details of Linux Operation Mode, can someone help me how I can start with, I am still a rookie in XQL Query.

 

TIA

 

VenuK by L2 Linker
  • 1825 Views
  • 3 replies
  • 0 Likes

Outlook stops syncing with Cortex XDR enabled

We have 2 Cortex tenants with a total of about 600 users. We encountered an issue where Outlook 365 will show "Needs password" and will not connect to Office 365 to sync. The only way to get it to sync is to stop the Cortex service. Once Outlook conn

...

Resolved! Cortex XDR - Brute force alert rule

Hi,

 

I need to create a brute force rule.

When endpoints with tag "CRITICAL" has "action_evtlog_description = An account failed to log on" and has more than 50 logs, create a CRITICAL alert.

 

Could you help pls.

 

Regards,

Automation of Reports

Hello Team,

 

  • We need to create automated XDR report to detect executions of “Python.exe” and “PowerShell.exe & PowerShell_ise.exe” in our environment.
  • Can we query a incident/alerts to make a report or suggest us how we can generate reports based on
...

Resolved! Get info from different dataset and compare

Hi,

 

I need to get failed logins from critical assets.

 

So I was trying to get tag "CRITICAL" in endpoints dataset and if there are any "event_type = ENUM.EVENT_LOG and action_evtlog_event_id = 4625 in xdr_data dataset.

 

Could you help pls

 

  • 2255 Posts
  • 86 Subscriptions
Top Liked Authors