Feature Request – LLDP/CDP Support for Network-Based Endpoint Discovery

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Feature Request – LLDP/CDP Support for Network-Based Endpoint Discovery

L0 Member

I would like to request a new feature for Cortex XDR that enables it to collect network information using the Link Layer Discovery Protocol (LLDP) and Cisco Discovery Protocol (CDP).

By capturing LLDP/CDP packets directly from the endpoint's network interface, Cortex XDR can accurately identify the switch and port to which a device is connected.
This would eliminate the need for external tools or network administrators to manually correlate endpoint location data, streamlining incident response and forensics.

CrowdStrike already provides this functionality, making it a valuable addition to the Cortex XDR feature set.
Since LLDP and CDP are transmitted in clear text, this feature can be implemented without additional components, simply by passively capturing network traffic on the endpoint’s interface.

 

The feature could be an optional setting within Cortex XDR, allowing organizations to enable or disable LLDP/CDP collection based on security policies.
The captured network metadata could be displayed in the XDR console under endpoint details, aiding security teams in network mapping and incident triage.
This feature would significantly improve endpoint visibility and security response capabilities in enterprise environments. I appreciate your consideration and look forward to any feedback on feasibility or implementation timelines.

1 accepted solution

Accepted Solutions

Community Team Member

Hi @WMartini ,

 

we can't process Feature Requests through the discussion forum

 

I'd recommend you reach out to a local SE who can submit the feature request for you.

If you then share the FR number here, other members can add their vote to it by reaching out to their sales teams.

 

Kind regards,

-Kim.

 

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

View solution in original post

2 REPLIES 2

Community Team Member

Hi @WMartini ,

 

we can't process Feature Requests through the discussion forum

 

I'd recommend you reach out to a local SE who can submit the feature request for you.

If you then share the FR number here, other members can add their vote to it by reaching out to their sales teams.

 

Kind regards,

-Kim.

 

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Hi,

 

The FR number: CXDR-I-4044

 

https://xdr.ideas.aha.io/ideas/CXDR-I-4044

 

Many thanks,

 

  • 1 accepted solution
  • 174 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!