- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-20-2025 04:17 PM
I would like to request a new feature for Cortex XDR that enables it to collect network information using the Link Layer Discovery Protocol (LLDP) and Cisco Discovery Protocol (CDP).
By capturing LLDP/CDP packets directly from the endpoint's network interface, Cortex XDR can accurately identify the switch and port to which a device is connected.
This would eliminate the need for external tools or network administrators to manually correlate endpoint location data, streamlining incident response and forensics.
CrowdStrike already provides this functionality, making it a valuable addition to the Cortex XDR feature set.
Since LLDP and CDP are transmitted in clear text, this feature can be implemented without additional components, simply by passively capturing network traffic on the endpoint’s interface.
The feature could be an optional setting within Cortex XDR, allowing organizations to enable or disable LLDP/CDP collection based on security policies.
The captured network metadata could be displayed in the XDR console under endpoint details, aiding security teams in network mapping and incident triage.
This feature would significantly improve endpoint visibility and security response capabilities in enterprise environments. I appreciate your consideration and look forward to any feedback on feasibility or implementation timelines.
03-21-2025 04:16 AM
Hi @WMartini ,
we can't process Feature Requests through the discussion forum
I'd recommend you reach out to a local SE who can submit the feature request for you.
If you then share the FR number here, other members can add their vote to it by reaching out to their sales teams.
Kind regards,
-Kim.
03-21-2025 04:16 AM
Hi @WMartini ,
we can't process Feature Requests through the discussion forum
I'd recommend you reach out to a local SE who can submit the feature request for you.
If you then share the FR number here, other members can add their vote to it by reaching out to their sales teams.
Kind regards,
-Kim.
03-21-2025 07:11 AM - edited 03-21-2025 07:32 AM
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!