Action #352 failed. Action description: Retrieve endpoint data from
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.
Hi all
i try to install cortex agent 7.8 on server core 2022 but it fails with little explanation
did someone success on it ?
=== Verbose logging started: 21-10-22 10:56:37 Build type: SHIP UNICODE 5.00.10011.00 Calling process: C:\Wind
...
Hello ,
Please help us with the process of blocking of IOC process coming from various campaigns in cortex XDR .
Regards,
Shashank
Hello,
Cortex XDR is changing the status of incidents from Resolved to Under Investigation automatically. Why is this happening?
Hello dear community!
Is there a way to hunt for named pipe communication?
BR
Rob
https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575
I would like to query XDR externally for the data stored in the Host Insights > Vulnerability Assessment page.
I looked through all of the available APIs, but none of them seem to have data related to CVEs. I would not be opposed to writing a custom
...
Hello dear communinty,
we would like to know, if there will be a functionality in the future like applocker or MDAC for whitelisting applications/scripts/etc.. If they are not in out WL, they cannot be executed and we get a information/alert.
T
...
Hello,
I would like to filter incidents on what kind of actions have been taken. Is this available or should I make a feature request somehow?
Ie. filter on all incidents containing alerts that have prevented as action. Or Filter out any where the
...
Hello PAN community !!
I'm new in this platform and I am a little lost here. I'm trying to create a query to list all endpoints of a specific endpoint group with all its incidents (malware,etc).
To get the endpointgroup and its endpoints I'm using
datas
...
Hi,
A number of our customers has complained about our signed PowerShell scripts being flagged and, in some cases, blocked by Cortex XDR.
The scripts in question can be found here:
https://stream.vulndetect.com/e/task.ps1
https://stream.vulndetec
...
Hello Team,
We intend to enable the Host Firewall feature in the Cortex XDR. Please give us a brief overview of how this feature works.
Hello ,
We are unable to see few servers in our endpoint list. But the user confirmed it has cortex installed in it and is enabled also particularly For Windows 2012 servers we're not able to set the proxy and for some hosts last seen connected dat
...
Hi,
Some Agents in Cortex DXR disappears then shows up after few days - no pattern at all
If my understanding is correct, if the Agents are disconnected or there's a connection lost, the Endpoint Status column will dictate it.
But the Agents in q
...
PoC Lab: Monitoring Malicious Chrome Extensions
By: @mfakhouri
Executive Summary
With the convenience Chrome extensions provide, such as ad blocking, enhanced web viewing, and improving user experiences, it is no surprise that malicious act
...Subject | Likes |
---|---|
3 Likes | |
2 Likes | |
2 Likes | |
1 Like | |
1 Like |