Cortex XDR Discussions
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Discussions

Welcome to the Cortex XDR Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4375 Views
  • 0 replies
  • 3 Likes

Palo Alto Cortex XDR exclusions/exceptions use case example article for solving VPN agent interoperability issues

Hello to All, I have made an interesting article about Cortex XDR use case for using isolation exclusions/exceptions when having VPN agent that blocks network traffic based on DNS FQDN Domains: https://live.paloaltonetworks.com/t5/general-articles/xdr-isolation-exceptions-and-exclusions-use-case/ta-p/515583

Resolved! A question from the Endpoint Administration Part 2 webinar: Alert ID

We often notice alert_id out of the numerical order, chronologically, sometimes way off. It appears like XDR is detecting something later and assigning an older timestamp but a new alert_id to detection. Can someone provide some detail/explanation on this observed behavior? Note: This question was asked during a customer success webinar: Endpo...

rtsedaka by L6 Presenter
  • 4502 Views
  • 3 replies
  • 0 Likes

Resolved! A question from the Endpoint Administration Part 2 webinar: Linux machines & Kernel Updates

There are some instances of Linux machines that are protected previously and then became unprotected or partially protected. As per checking on them, it was because the kernel version was upgraded to the latest version and is still not listed on the supported versions from the KB. Is it safe to say that we should just configure the policy to use...

rtsedaka by L6 Presenter
  • 2594 Views
  • 1 replies
  • 0 Likes

A question from the Alert Tuning Operations Webinar: Signing level in a child process

We have a mac-device on which even a reinstalled chrome creates child processes (Google Chrome Helper) that are apparently below the signing level of the parent process. Their signatures seem to be valid. Seems like whitelisting the hash of the initiator is not the best idea. What would be the best process if a child's process is blocked due to ...

rtsedaka by L6 Presenter
  • 2567 Views
  • 1 replies
  • 0 Likes