Security Operations
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Cortex XDR, XSOAR, and Xpanse discussions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Security Operations
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Cortex XDR, XSOAR, and Xpanse discussions.

Browse the Community

Cortex XDR Discussions

Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.

1172 Posts

Cortex XSOAR Discussions

Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

617 Posts

Cortex Xpanse Discussions

Cortex Xpanse builds a system of record that is the authoritative source for an organization’s global Internet assets; it knows your attack surface so you can own it before someone else.

3 Posts

Cortex XSIAM Discussions

Cortex XSIAM, the autonomous security platform powering the Modern SOC, operates across cloud and enterprise security operations, providing true end-to-end management of threats wherever they originate.

1 Posts

Activity in Security Operations

Resolved! Threat ID #9999' generated by PAN NGFW

Hello,

 

I have turned off alerts on NGFW for Private URL, but I still get threat ID #9999. 

 

Can somebody a little bit more explain what this threat ID means? I am trying to clean it up, but still get these alerts.

And it is not any kind of malicious tr

...

LukasB by L1 Bithead
  • 4744 Views
  • 5 replies
  • 0 Likes

Searching for multiple hashes on cortex XDR

Does anyone know a way to search for multiple hashes on Cortex XDR?

file_search = existing_files does not allow any operators other than "=" for the sha values and you can't string multiple in a query. 

I feel like I'm missing something and there sho

...

rufat87 by L1 Bithead
  • 393 Views
  • 3 replies
  • 0 Likes

Possible Values for event_types

Hello Community, 

 

I am trying to understand Palo Alto XDR logs fetched using API(XQL Query). 

I am using dataset as xdr_data, want to know what all event_types can come under this dataset. 

For ex: EVENT_LOG. 

What are the possible values we can ge

...

How to know if a zip file is encrypted in XSOAR

Hello,

We'd like to know if a zip file is encrypted inside a playbook or a automation. The way in which XSOAR works with these files does not allow the use of python libraries. Is there a way through the File context value to know if the file is encr

...

Josep by L4 Transporter
  • 111 Views
  • 3 replies
  • 0 Likes

agent intall exceed license number of agents

I read the relevant documents, but I don't quite understand them. I hope someone can confirm them for me.

reference articale url :https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-overview/cortex-xdr-licenses/cortex-x

...

Felixcao by L3 Networker
  • 2444 Views
  • 4 replies
  • 0 Likes