Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
About Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.

Discussions

Resolved! Penetration testing for publicity

Hello!

 

are we allowed as cortex xdr customers to penetrate the security suite through other researchers/analysts like TPSC https://thepcsecuritychannel.com/ ? They will also put a video on youtube. 

 

Thanks

 

BR

 

Rob

 

 

Cyber1985 by L3 Networker
  • 2369 Views
  • 4 replies
  • 0 Likes

Threat Intelligence Feed (IP-Adresses)

Hello!

 

we have bought a DNS SEC product with a TI Feed (with bad IPs - about 900k). 

How can we integrate this into Cortex XDR? 

It is a textfile, which can be downloaded through a simple link. 

IP1

IP2

...

We need a way to put this IP-Check somewhere on t

...

Cyber1985 by L3 Networker
  • 1583 Views
  • 2 replies
  • 0 Likes

Can recognize Signer but not signature

I have a security event, I clicked in and found that the CGO signature is unsigned, but when I create an alert exception, it recognizes the signer, why is that? The signature is not recognized, but the signer can be recognized

12.png
13.png
Grady by L2 Linker
  • 1532 Views
  • 1 replies
  • 0 Likes

Resolved! Test alerts in Cortex xdr

Is there a built-in way to generate a test alert either from an agent installed on a client machine or through the XDR portal itself?

 

I currently have an agent ver 7.6.2 installed on a windows box and I'd like to create a test alert that will be visi

...

Resolved! Admin password changes

I received an email yesterday saying the passwords for admin accounts will need to be updated before April14th.

I just wanted to confirm that only admin passwords are being changed. Will there be any changes to integration API keys?  

Cortex Subscription license doubt

We have deployed more than 800 agents in the network. Currently, we have a trial license but they will purchase the license the next month. 

 

If the actual license will come did we have to again reinstall the agents. 

 

 

Resolved! XDR 3.2 Broker VM Kernel version

Hello ,

We are using Cortex XDR Prevent 3.2 with 2 Broker VMs for Proxy access  .

I guess Broker VMs are Linux appliance . So is there any way to find the Linux kernel version which these VMs are running ?

Thanks in advance for response

Balaraju by L2 Linker
  • 1974 Views
  • 2 replies
  • 0 Likes

XdrAgentCleaner Execution Monitoring

Is anyone monitoring XdrAgentCleaner execution? And if so i have a question, lets say when we run the XdrAgentCleaner, before the agent cleans all the Cortex traces, does it sends the EDR telemetry to cloud so in case if XdrAgentCleaner is used malic

...

  • 1874 Posts
  • 78 Subscriptions
This widget could not be displayed.
Top Liked Authors