Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4319 Views
  • 0 replies
  • 3 Likes

Resolved! Exception Exploit Module

Hello Community, I would like to create an exception rule for an IIS worker process w3wp.exe, which module would be the appropriate one where the exception would reside. Based on the documentation here EXPLOIT SECURITY POLICY offers protection against this process, but in the exception configuration which module do I select when adding in th...

brownchris_0-1692392318707.png

Resolved! Server in the DMZ- unable to Live Terminal Into

All, When looking through the log file of the agent, I ran across this. Can anyone tell me what its for and why is it missing? This was a fresh install of the latest Cortex agent. Thanks. Payload archive file \"C:\\ProgramData\\Cyvera\\LocalSystem\\Download\\content\\cortex-xdr-payload.zip\" does not exist"

How to use XQL parse_timestamp

I am trying to convert a string to a timestamp object and cannot understand how the parse_timestamp function works. My string is as follow : "2023-08-17T17:40:38.000246+0300" My XQL query is as follow : alter timestamp = parse_timestamp("%Y-%m-%dT%H:%M:%S", format_string("%s", <field containing the timestamp string>)) This is clearly...

unlucky by L0 Member
  • 4653 Views
  • 2 replies
  • 0 Likes

XDR agent Auto upgrade Schedule settings in agent configurations

We recently enabled Auto upgrade on our system. We selected " Only maintenance releases in a specific version " configured the agent Configurations as below: Although when I checked the Agent audit logs I see that the upgrades started at Aug 17th 2023 06:10:10 AM CDT and last was around Aug 17th 2023 15:04:18 CDT. So I want to know if we have a...

Shaveta_0-1692302820890.png
Shaveta by L1 Bithead
  • 1430 Views
  • 1 replies
  • 0 Likes

Resolved! Cortex XDR 7.9 CE not installing on Windows Server 2008 R2

Hi, There is Windows Server 2008 R2 server which had Cortex XDR 7.9 installed. As this version is end of support in next few weeks, I decided to install 7.9 CE, which according to compatibility matrix: Windows • Cortex XDR Compatibility Matrix • Reader • Palo Alto Networks documentation portal should work on the system. However when I try to i...

Beyond Corp configuration to use in Context-Aware Access

Hi, I would like to know how I integrate Cortex XDR with Context-Aware Access from Google's Beyond Corp product. Analyzing the existing documentation, I got the impression that I need to create a rule like this in CAA: device.vendors["cortex"].is_managed_device == true && device.vendors["cortex"].data["complianceState"] == "compliant...

mjunior by L0 Member
  • 1553 Views
  • 1 replies
  • 0 Likes

Resolved! Cortex XDR on Ubuntu doesn't recognise vulnerabilities correctly

Hi, Cortex XDR agent (version 8.1.0.107064) installed on fully patched Ubuntu server 22.04 doesn’t recognise vulnerabilities correctly. It shows over 330 false positives. Some examples below: CVE-2015-34-5 – ntp vulnerable version prior 4.2.8p2-RC2 – recently installed 4.2.8p15 CVE-2019-13638 – patch vulnerable version 2.7.6 – recently install...

2008 R2 OS version

HI Team We have a servers in the console with 2008 R2 OS version, so when we tried to upgrade the XDR agent version on these servers through console getting "unsupported older OS version". If XDR agent version expires on the server or machine we don't get updates so what is the remedy ?

Cortex XDR Pro should detect and control Backup Software and backup destinations.

Today, one of the most common techniques for a intruder today is to use a valid backup system to make a image of the system and in what way steal all the data of the server.. Werefore i want a new module in the Cortex XDR what will detect the backup software. - The first installed backup software will just be notified upon. - As a admin i should...

  • 2583 Posts
  • 95 Subscriptions
Top Solution Authors