Security Operations
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Cortex XDR, XSOAR, and Xpanse discussions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Security Operations
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Cortex XDR, XSOAR, and Xpanse discussions.

Browse the Community

Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

2538 Posts

Cortex XSOAR Discussions

Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

1288 Posts

Cortex Xpanse Discussions

Cortex Xpanse builds a system of record that is the authoritative source for an organization’s global Internet assets; it knows your attack surface so you can own it before someone else.

10 Posts

Cortex XSIAM Discussions

Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.

139 Posts

Activity in Security Operations

Windows Installer DB: Current agent installation is missing

I am currently experiencing an issue while attempting to upgrade agents in the Cortex XDR console. The upgrade process fails with the following error message: "Windows Installer DB: Current agent installation is missing." I attempted to clean the endpoint; however, the process was unsuccessful. I would like to ask if there is any alternative...

Create a IOC without incident

Good morning, Today I would like to create a block for two malicious files that I found in our environment. I noticed that I can create an IOC to block paths, file names, IPs, etc. I have already created an IOC using a wildcard for the file name: PDFEditor_*.exe, but I would also like to block the process without generating an incident. Is that ...

Cortex XDR Pro / Browser extensions

Has anyone ever configured their environment to detect on unauthorized or unsupported browser extensions? Or conduct a threat hunt based on known facts? We've seen some slip through the cracks and I know Cortex doesn't natively detect abused or malicious extensions. Any XQL ideas out there perhaps?

Reconnect after endpoint cleanup

Hello, I'm thinking about using the Endpoint Administration Cleanup tool. However, I wanted to be sure if an endpoint is mistakenly deleted would shows up again in our tenant (if connected in the next 90 days). Did anyone has experienced it yet? Is this supposed to be the same if an endpoint is in "Connection Lost" then is connected?If so, i...

Resolved! XDR add more values to incident classification

Hi everyone, When I close each incident, I need to add the CSIRT taxonomy flags (from the ENISA Reference Incident Classification Taxonomy: https://www.enisa.europa.eu/publications/reference-incident-classification-taxonomy) to the Cortex XDR case. Does anyone know if that is possible?

tlmarques by L4 Transporter
  • 102 Views
  • 4 replies
  • 0 Likes

Playbook stuck after upgrade

Hi! I have a playbook that gets stuck in a very weird way. I seek for community help as after my last session with product support, i do not seem to go anywhere as there were no obvious platform errors, they blame the playbook. 😞 Since the upgrade to the latest 6.14 build, one popular custom playbook is stuck on specific conditional task. It ...

support.png
Antanas by L2 Linker
  • 22 Views
  • 0 replies
  • 0 Likes

Cortex Management Report

I want to know if I can generate a report of Cortex's actions over the last year or 3 months, such as what he blocked, quarantined, isolated, etc., but in a graph format. I tried using a widget library, but I can't find a way to represent that action. What can I do?

Inquiry regarding Tenant Backu & Recovery

I am looking for detailed information regarding the backup and recovery lifecycle for a Cortex XDR tenant. Specifically, I have the following questions: Automated Backups: Does Palo Alto Networks perform regular backups of tenant-specific configurations (Security Policies, Profiles, XQL queries, etc.)? If so, what is the standard frequency? ...

ServiceNow CMDB data to XSIAM

Hi, We have integrated XSIAM with ServiceNow CMDB. We want to pull critical assets from the CMDB into XSIAM using an API and we have to do feature field configuration for these critical assets. Currently, I only see an option to upload a static file in the feature field configuration ( Host/ User/IPaddress) Could someone please help with the fol...

XSIAM Email Communication

In XSIAM, we need a way for analysts to send email updates at different stages of an incident — like when it is received, contained, and recovered. Each case should have its own email chain that includes all previous emails for that case. To support this, we have added a button in the case template where analysts can write and send emails. When ...

Resolved! Correlating a file path to application inventory

Hello, I am gathering an application inventory for endpoints in our environment. As part of this inventory, I'd like to include the install path for these applications. Currently Host Inventory XQL dataset only showcases uninstall strings in the applications field. Assistance in correlating an install path via joining datasets or something si...

Resolved! Cortex XDR Tenant Auto-Upgrade 3.17 → 5.0: UI mixed theme, AI pages stuck loading, Marketplace/Playbook Catalog empty + ingestion quota warning

I tried to open a Support case, but none of the available issue categories allowed me to create a case and I was redirected to Live Community for assistance. I’m posting here to get guidance on the likely root cause and recommended next steps. After an automated upgrade from 3.x to 5.0, multiple UI and feature issues appeared. Pages look like ...

XDR 5.0 - opinion

Cortex Cortex XDR 5.0 tenant. What's your opinion https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-5.x-Release-Notes/Release-Information

tlmarques_0-1770656806817.png
tlmarques by L4 Transporter
  • 254 Views
  • 8 replies
  • 0 Likes

Resolved! Sending USB Alerts via syslog (Cortex XDR)

Hello, We have received a request asking whether it is possible for administrators to receive alert emails whenever a USB device is connected to any endpoints.(*Currently, the USB policy in Exploit – Device Configuration is set to Read Only.) (* I think the adminster wants to get the log [Inventory-Device Control Violations]) We attempted to c...

YSONG464633_0-1770612974843.png
Register or Sign-in
Top Solution Authors